CNNVD-202508-979 Information

CNNVD ID

CNNVD-202508-979

CVE-2025-42935

  • CNNVD Published: 2025-08-12

Description (Chinese)

SAP Internet Communication Manager(SAP ICM)和SAP NetWeaver Application Server ABAP都是德国思爱普(SAP)公司的产品。SAP Internet Communication Manager是一个 SAP NetWeaver 应用程序服务器的组件。用于接收和发送 Web 请求(HTTP、HTTPS、SMTP)。SAP NetWeaver Application Server ABAP是一个运行和开发基于ABAP语言的应用程序的平台。 SAP Internet Communication Manager和SAP NetWeaver Application Server ABAP存在日志信息泄露漏洞,该漏洞源于日志文件访问控制不当,可能导致信息泄露。

Description (English)

SAP Internet Community Manager (SAP ICM) and SAP NetWeaver Application Server ABAP are products of SAP Germany. SAP Internet Community Manager is a component of the SAP NetWeaver application server. For receiving and sending Web requests (HTTP, HTTPS, SMTP). SAP NetWeaver Application Server ABAP is a platform for the operation and development of applications based on the AABAP language. SAP Internet Communications Manager and SAP NetWeaver Application Server AABAP had a log leak, which stemmed from inadequate log file access controls that could lead to leaking information.

Hazard Level

High

Vulnerability Type

日志信息泄露

Affected Vendor

思爱普

Published

2025-08-12

Last Modified

2026-02-24

References

https://me.sap.com/notes/3601480 https://url.sap/sapsecuritypatchday

Patch

https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2025.html

Share on: