CVE-2025-42877: SAP SE SAP Web Dispatcher, Internet Communication Manager And SAP Content Server

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploit logical errors that lead to a memory corruption vulnerability. This results in high impact on the availability with no impact on confidentiality or integrity of the application.

Affected products

  • SAP SE SAP Web Dispatcher, Internet Communication Manager And SAP Content Server: version 7.54 only

Published 2025-12-09. Last modified 2026-10-07.