Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3662324
was released on
09.12.2025 and deals with
"[CVE-2025-42904] Information Disclosure vulnerability in Application Server ABAP" within Kernel.
We advice you to follow the instructions, to resolve
information disclosure
with a
medium potential for exploitation
in component BC-ABA-LI.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as part of maintenance.
Information disclosure is when an application fails to properly protect sensitive and confidential information from
parties that are not supposed to have access to the subject matter in normal circumstances.
Carefully review every information disclosure vulnerablity in regards to disclosure obligations post-GDPR for
‘Personal data’ under the Data Protection Act 2018.
Risk specification
A vulnerability in the SAP Application Server ABAP allows an authenticated attacker to read unmasked values displayed in ABAP lists, which can result in unauthorized disclosure of data.
Solution
The issue was fixed by restoring masking in ABAP lists and reverting the regression introduced in SAP Note 3633999.
The advisory is valid for
- KERNEL 7.53 54
- KERNEL 7.54 33
- KERNEL 7.77 50
- KERNEL 7.89 33
- KERNEL 7.93 27
- KERNEL 9.16 5
- KERNEL 9.17
- KRNL64UC 7.53 54
