4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description
A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low impact on confidentiality with no impact on integrity or availability.
Basic Information
ID
CVE-2025-42903
Source
sap
Published
Oct 14, 2025 at 00:17
Affected Product
Vendor
SAP_SE
Product
SAP Financial Service Claims Management
Version
INSURANCE 803
Affected Versions
SAP_SE SAP Financial Service Claims Management INSURANCE 803
SAP_SE SAP Financial Service Claims Management 804
SAP_SE SAP Financial Service Claims Management 805
SAP_SE SAP Financial Service Claims Management 806
SAP_SE SAP Financial Service Claims Management S4CEXT 107
SAP_SE SAP Financial Service Claims Management 108
SAP_SE SAP Financial Service Claims Management 109
SAP_SE SAP Financial Service Claims Management 804
SAP_SE SAP Financial Service Claims Management 805
SAP_SE SAP Financial Service Claims Management 806
SAP_SE SAP Financial Service Claims Management S4CEXT 107
SAP_SE SAP Financial Service Claims Management 108
SAP_SE SAP Financial Service Claims Management 109