SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, the attacker needs developer authorization in a specific Application Server ABAP to make changes in the code, and the victim needs to execute by using SAP GUI for Windows. This could trigger automatic NTLM authentication, potentially exposing hashed credentials to an attacker. As a result, it has a high impact on the confidentiality.
History

Tue, 12 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Aug 2025 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap sap Gui
Vendors & Products Sap
Sap sap Gui

Tue, 12 Aug 2025 02:30:00 +0000

Type Values Removed Values Added
Description SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, the attacker needs developer authorization in a specific Application Server ABAP to make changes in the code, and the victim needs to execute by using SAP GUI for Windows. This could trigger automatic NTLM authentication, potentially exposing hashed credentials to an attacker. As a result, it has a high impact on the confidentiality.
Title Information Disclosure in SAP GUI for Windows
Weaknesses CWE-250
References
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-08-12T02:05:44.263Z

Updated: 2025-08-12T15:57:37.252Z

Reserved: 2025-04-16T13:25:37.187Z

Link: CVE-2025-42943

cve-icon Vulnrichment

Updated: 2025-08-12T15:57:11.560Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-12T03:15:26.987

Modified: 2025-08-12T14:25:33.177

Link: CVE-2025-42943

cve-icon Redhat

No data.