In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information that should otherwise be restricted. The attacker does not have the ability to modify the information or to make the information unavailable.
                
            References
                    | Link | Resource | 
|---|---|
| https://me.sap.com/notes/3542698 | Permissions Required | 
| https://url.sap/sapsecuritypatchday | Patch | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    24 Oct 2025, 19:22
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | |
| First Time | Sap Sap sap Basis | |
| References | () https://me.sap.com/notes/3542698 - Permissions Required | |
| References | () https://url.sap/sapsecuritypatchday - Patch | |
| CPE | cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:758:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:912:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:914:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:913:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:756:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:755:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:757:*:*:*:*:*:*:* | 
14 Jan 2025, 01:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-01-14 01:15
Updated : 2025-10-24 19:22
NVD link : CVE-2025-0058
Mitre link : CVE-2025-0058
CVE.ORG link : CVE-2025-0058
JSON object : View
Products Affected
                sap
- sap_basis
CWE
                
                    
                        
                        CWE-639
                        
            Authorization Bypass Through User-Controlled Key
