CVE-2025-0058: SAP Basis
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information that should otherwise be restricted. The attacker does not have the ability to modify the information or to make the information unavailable.
Affected products
- SAP SAP Basis: version 753 only; version 754 only; version 755 only; version 756 only; version 757 only; version 758 only; …
Published 2025-01-14. Last modified 2026-06-17.