SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenticated attacker to access information within systems, resulting in privilege escalation. On successful exploitation, this could result in disclosure of highly sensitive information. This has no impact on integrity, and availability.
History

Tue, 11 Feb 2025 06:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 01:00:00 +0000

Type Values Removed Values Added
Description SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenticated attacker to access information within systems, resulting in privilege escalation. On successful exploitation, this could result in disclosure of highly sensitive information. This has no impact on integrity, and availability.
Title Insecure Key & Secret Management vulnerability in SAP GUI for Windows
Weaknesses CWE-921
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-02-18T18:06:30.865Z

Reserved: 2025-01-27T08:57:48.544Z

Link: CVE-2025-24870

cve-icon Vulnrichment

Updated: 2025-02-11T05:51:50.131Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-11T01:15:11.280

Modified: 2025-02-18T18:15:33.987

Link: CVE-2025-24870

cve-icon Redhat

No data.