Medium severity6.5NVD Advisory· Published Jan 14, 2025· Updated Jun 17, 2026
CVE-2025-0058
CVE-2025-0058
Description
In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information that should otherwise be restricted. The attacker does not have the ability to modify the information or to make the information unavailable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:755:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:756:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:757:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:758:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:912:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:913:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:914:*:*:*:*:*:*:*
- SAP_SE/SAP Business Workflow and SAP Flexible Workflowv5Range: SAP_BASIS 753
Patches
Vulnerability mechanics
References
2- url.sap/sapsecuritypatchdaynvdPatch
- me.sap.com/notes/3542698nvdPermissions Required
News mentions
0No linked articles in our index yet.