CVE-2025-0058 is a medium-severity information disclosure vulnerability affecting SAP Business Workflow and SAP Flexible Workflow. An authenticated attacker can exploit a parameter manipulation in a legitimate request to view restricted sensitive information, though they cannot modify or disrupt it. The CVSS score is 6.5, indicating network access with low attack complexity and requiring low privileges, resulting in high confidentiality impact. Currently, there is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
753CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:* | ||
754CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:* | ||
755CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:755:*:*:*:*:*:*:* | ||
756CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:756:*:*:*:*:*:*:* | ||
757CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:757:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.