CVE-2025-24870

6.0
MEDIUMCVSS v3.1 Base Score
0.16%
LOW RiskEPSS (6th percentile)

SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenticated attacker to access information within systems, resulting in privilege escalation. On successful exploitation, this could result in disclosure of highly sensitive information. This has no impact on integrity, and availability.

Published: 2/11/2025
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

6MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

EPSS Score (Exploitation Probability)

0.16%LOW Exploitation Risk
6th percentile

This vulnerability has a 0.16% probability of being exploited in the next 30 days, ranking higher than 6% of all scored CVEs.

CWE Classification

Advertisement