The following table lists the changes that have been made to the
CVE-2025-0056 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by [email protected]Jan. 14, 2025
Action Type Old Value New Value Added Description SAP GUI for Java saves user input on the client PC to improve usability. An attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the disclosed data could range from non-critical data to highly sensitive data, causing high impact on confidentiality of the application. Added CVSS V3.1 AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N Added CWE CWE-497 Added Reference https://me.sap.com/notes/3502459 Added Reference https://url.sap/sapsecuritypatchday