CVE-2025-0071: SAP SE SAP Web Dispatcher And Internet Communication Manager
Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.
SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes unencrypted passwords in the logs, causing a high impact on the confidentiality of the application. There is no impact on integrity or availability.
Affected products
- SAP SE SAP Web Dispatcher And Internet Communication Manager: version 7.54 only; version 7.77 only; version 7.89 only; version 7.93 only; version 9.14 only
Published 2025-03-11. Last modified 2026-06-17.