Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 21 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap financial Service Claims Management |
|
| Vendors & Products |
Sap
Sap financial Service Claims Management |
Tue, 14 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Oct 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low impact on confidentiality with no impact on integrity or availability. | |
| Title | User Enumeration and Sensitive Data Exposure via RFC Function in SAP Financial Service Claims Management | |
| Weaknesses | CWE-204 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-10-14T15:22:42.641Z
Reserved: 2025-04-16T13:25:25.736Z
Link: CVE-2025-42903
Updated: 2025-10-14T15:22:37.972Z
Status : Deferred
Published: 2025-10-14T01:15:32.137
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-42903
No data.
OpenCVE Enrichment
Updated: 2025-10-21T13:10:40Z