CVE-2025-42903 - CVE House
Back to Database
Status published Medium CVE-2025-42903

User Enumeration and Sensitive Data Exposure via RFC Function in SAP Financial Service Claims Management

Vulnerability Description

A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low impact on confidentiality with no impact on integrity or availability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-42903

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SAP Financial Service Claims Management
Vulnerable Versions:
INSURANCE 803, 804, 805, 806, S4CEXT 107, 108, 109

Timeline

Official Publish: October 14th, 2025
Last Modified: October 14th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.