CVE-2025-42877
7.5SAP · Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server
SAP Web Dispatcher, ICM, and SAP Content Server contain a memory corruption vulnerability due to logical errors, allowing unauthenticated attackers to trigger a denial of service.
Executive summary
An unauthenticated memory corruption vulnerability in SAP Web Dispatcher, ICM, and SAP Content Server poses a significant risk to application availability.
Vulnerability
This vulnerability involves an out-of-bounds write (CWE-787) caused by logical errors, which can be triggered by an unauthenticated attacker over the network. The flaw specifically impacts application availability by causing memory corruption.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk primarily targeting service availability. Successful exploitation allows an unauthenticated actor to crash critical SAP infrastructure, leading to potential operational disruption and loss of business continuity. While confidentiality and integrity are not directly compromised, the downtime resulting from this memory corruption could have severe cascading effects on dependent enterprise systems.
Remediation
Immediate Action: Review SAP Security Note 3677544 to identify and apply the necessary patches for the affected SAP kernel and component versions.
Proactive Monitoring: Monitor system logs for unusual error patterns, specifically crashes or unexpected restarts of the Web Dispatcher or ICM services.
Compensating Controls: Implement network-level access controls to restrict access to management interfaces, ensuring only trusted IP addresses can reach vulnerable SAP components.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS rating and the potential for remote exploitation by unauthenticated actors, organizations should treat this vulnerability with high priority. Administrators must consult the official SAP security portal referenced in the metadata to obtain the relevant patches and ensure their environments are updated to the corrected versions. Immediate deployment of these updates is the most effective method to mitigate the risk of service interruption.