Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-0058— Information Disclosure vulnerability in SAP Business Workflow and SAP Flexible Workflow

CVSS 6.5 · Medium EPSS 0.12% · P31
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-0058

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Information Disclosure vulnerability in SAP Business Workflow and SAP Flexible Workflow
Source: NVD (National Vulnerability Database)
Vulnerability Description
In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information that should otherwise be restricted. The attacker does not have the ability to modify the information or to make the information unavailable.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: NVD (National Vulnerability Database)
Vulnerability Title
SAP Business Workflow和SAP Flexible Workflow 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SAP Business Workflow和SAP Flexible Workflow都是德国思爱普(SAP)公司的产品。SAP Business Workflow是用于执行业务流程的关键组件,它允许用户设计、实施和管理业务流程,确保流程的合规性,并通过自动化减少手动操作的需要。SAP Flexible Workflow是一个灵活工作流程管理程序。 SAP Business Workflow和SAP Flexible Workflow存在安全漏洞,该漏洞源于经过身份验证的攻击者可以操纵合法资源请求中的参数
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
SAP_SESAP Business Workflow and SAP Flexible Workflow SAP_BASIS 753 -

II. Public POCs for CVE-2025-0058

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-0058

登录查看更多情报信息。

Same Patch Batch · SAP_SE · 2025-01-14 · 14 CVEs total

CVE-2025-00669.9 CRITICALInformation Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform (Inter
CVE-2025-00709.9 CRITICALImproper Authentication in SAP NetWeaver ABAP Server and ABAP Platform
CVE-2025-00638.8 HIGHSQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
CVE-2025-00618.7 HIGHMultiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform
CVE-2025-00697.8 HIGHDLL Hijacking vulnerability in SAPSetup
CVE-2025-00606.5 MEDIUMMultiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform
CVE-2025-00676.3 MEDIUMMissing Authorization check in SAP NetWeaver Application Server Java
CVE-2025-00556.0 MEDIUMInformation Disclosure vulnerability in SAP GUI for Windows
CVE-2025-00566.0 MEDIUMInformation Disclosure vulnerability in SAP GUI for Java
CVE-2025-00596.0 MEDIUMInformation Disclosure vulnerability in SAP NetWeaver Application Server ABAP (application
CVE-2025-00535.3 MEDIUMInformation Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP
CVE-2025-00574.8 MEDIUMCross-Site Scripting vulnerability in SAP NetWeaver AS JAVA (User Admin Application)
CVE-2025-00684.3 MEDIUMMissing Authorization check in Remote Function Call (RFC) in SAP NetWeaver Application Ser

IV. Related Vulnerabilities

V. Comments for CVE-2025-0058

No comments yet


Leave a comment