SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, the attacker needs developer authorization in a specific Application Server ABAP to make changes in the code, and the victim needs to execute by using SAP GUI for Windows. This could trigger automatic NTLM authentication, potentially exposing hashed credentials to an attacker. As a result, it has a high impact on the confidentiality.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 12 Aug 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sap
Sap sap Gui |
|
Vendors & Products |
Sap
Sap sap Gui |
Tue, 12 Aug 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, the attacker needs developer authorization in a specific Application Server ABAP to make changes in the code, and the victim needs to execute by using SAP GUI for Windows. This could trigger automatic NTLM authentication, potentially exposing hashed credentials to an attacker. As a result, it has a high impact on the confidentiality. | |
Title | Information Disclosure in SAP GUI for Windows | |
Weaknesses | CWE-250 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published: 2025-08-12T02:05:44.263Z
Updated: 2025-08-12T15:57:37.252Z
Reserved: 2025-04-16T13:25:37.187Z
Link: CVE-2025-42943

Updated: 2025-08-12T15:57:11.560Z

Status : Awaiting Analysis
Published: 2025-08-12T03:15:26.987
Modified: 2025-08-12T14:25:33.177
Link: CVE-2025-42943

No data.