Vulnerability Description
SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes unencrypted passwords in the logs, causing a high impact on the confidentiality of the application. There is no impact on integrity or availability.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-0071?
CVE-2025-0071 is a vulnerability with a CVSS score of 4.9 (MEDIUM). SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes unencrypted password...
How severe is CVE-2025-0071?
CVE-2025-0071 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-0071?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.