CVE-2025-24870 describes a vulnerability in SAP GUI for Windows and its RFC service where credentials are improperly stored in memory, allowing an unauthenticated attacker to access sensitive information and escalate privileges. This local attack has low complexity and can lead to the disclosure of highly sensitive data, though it does not impact integrity or availability. With a CVSS score of 6.0 (Medium), there is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SAP SE | SAP GUI For Windows | BC-FES-GUI 8.00CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.