7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploit logical errors that lead to a memory corruption vulnerability. This results in high impact on the availability with no impact on confidentiality or integrity of the application.
Basic Information
ID
CVE-2025-42877
Source
sap
Published
Dec 9, 2025 at 02:14
Affected Product
Vendor
SAP_SE
Product
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
Version
KRNL64UC 7.53
Affected Versions
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server KRNL64UC 7.53
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server WEBDISP 7.53
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server 7.54
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server XS_ADVANCED_RUNTIME 1.00
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server SAP_EXTENDED_APP_SERVICES 1
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server CONTSERV 7.53
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server KERNEL 7.53
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server WEBDISP 7.53
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server 7.54
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server XS_ADVANCED_RUNTIME 1.00
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server SAP_EXTENDED_APP_SERVICES 1
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server CONTSERV 7.53
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server KERNEL 7.53