CVE-2025-42904CWE-549

Information Disclosure vulnerability in Application Server ABAP

Medium · published December 9, 2025

CVSS v3.1
6.5
EPSS
0%
Percentile
25.9
In the wild
Unconfirmed
What it is

Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked values displayed in ABAP Lists. Successful exploitation could lead to unauthorized disclosure of data, resulting in a high impact on confidentiality without affecting integrity or availability.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00332 · 25.9th percentile
Weakness
CWE-549 · Missing Password Field Masking
Published
2025-12-09T02:15Z
EPSS history
Timeline
  • 09 DEC 02:15Z
    Information Disclosure vulnerability in Application Server ABAP
    cvelistv5