CVE-2025-42997: SAP SE SAP Gateway Client
Medium severity, CVSS 6.6. EPSS: 0.3% chance of exploitation in the next 30 days.
Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due to the possibility of influencing application behavior or performance through misuse of the exposed data, this may potentially lead to low impact on confidentiality, integrity, and availability.
Affected products
- SAP SE SAP Gateway Client: version 753 only; version 754 only; version 755 only; version 756 only; version 757 only; version 758 only
Published 2025-05-13. Last modified 2026-06-17.