# CVE-2025-42904

## Summary

- **CVE ID:** CVE-2025-42904
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-549
- **Published:** Dec 9, 2025
- **Last Modified:** Mar 13, 2026

## Description

Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked values displayed in ABAP Lists. Successful exploitation could lead to unauthorized disclosure of data, resulting in a high impact on confidentiality without affecting integrity or availability.

## Affected Products

- SAP_SE — Application Server ABAP (KRNL64UC 7.53)
- SAP_SE — Application Server ABAP (KERNEL 7.53)
- SAP_SE — Application Server ABAP (7.54)
- SAP_SE — Application Server ABAP (7.77)
- SAP_SE — Application Server ABAP (7.89)
- SAP_SE — Application Server ABAP (7.93)
- SAP_SE — Application Server ABAP (9.16)
- SAP_SE — Application Server ABAP (9.17)

## References

- [CNA](https://url.sap/sapsecuritypatchday)
- [CNA](https://me.sap.com/notes/3662324)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.33%
- **EPSS Percentile:** 26.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._