CVE-2025-42903 - User Enumeration and Sensitive Data Exposure via RFC Function in SAP Financial Service Claims Management
CVE ID : CVE-2025-42903
Published : Oct. 14, 2025, 1:15 a.m. | 1 hour, 24 minutes ago
Description : A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low impact on confidentiality with no impact on integrity or availability.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 14, 2025, 1:15 a.m. | 1 hour, 24 minutes ago
Description : A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low impact on confidentiality with no impact on integrity or availability.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...