CVE-2025-42878: SAP SE SAP Web Dispatcher And Internet Communication Manager Icm
High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.
SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability and low impact on integrity and of the application.
Affected products
- SAP SE SAP Web Dispatcher And Internet Communication Manager Icm: version 7.22EXT only; version 7.53 only; version 7.54 only; version 7.77 only; version 7.89 only; version 7.93 only; …
Published 2025-12-09. Last modified 2026-10-07.