CVE 7.5 HIGH

Memory Corruption vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server_CVE-2025-42877

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploit logical errors that lead to a memory corruption vulnerability. This results in high impact on the availability with no impact on confidentiality or integrity of the application.

Basic Information

ID CVE-2025-42877
Source sap
Published Dec 9, 2025 at 02:14

Affected Product

Vendor SAP_SE
Product SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
Version KRNL64UC 7.53
Affected Versions SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server KRNL64UC 7.53
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server WEBDISP 7.53
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server 7.54
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server XS_ADVANCED_RUNTIME 1.00
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server SAP_EXTENDED_APP_SERVICES 1
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server CONTSERV 7.53
SAP_SE SAP Web Dispatcher, Internet Communication Manager and SAP Content Server KERNEL 7.53

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.