CVE 4.3 MEDIUM

User Enumeration and Sensitive Data Exposure via RFC Function in SAP Financial Service Claims Management_CVE-2025-42903

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low impact on confidentiality with no impact on integrity or availability.

Basic Information

ID CVE-2025-42903
Source sap
Published Oct 14, 2025 at 00:17

Affected Product

Vendor SAP_SE
Product SAP Financial Service Claims Management
Version INSURANCE 803
Affected Versions SAP_SE SAP Financial Service Claims Management INSURANCE 803
SAP_SE SAP Financial Service Claims Management 804
SAP_SE SAP Financial Service Claims Management 805
SAP_SE SAP Financial Service Claims Management 806
SAP_SE SAP Financial Service Claims Management S4CEXT 107
SAP_SE SAP Financial Service Claims Management 108
SAP_SE SAP Financial Service Claims Management 109

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.