CVE Vulnerabilities

CVE-2025-43005

Plaintext Storage of a Password

Published: May 13, 2025 | Modified: May 13, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms used by the GuiXT application to store user credentials. While this issue does not impact the Integrity or Availability of the application, it may have a Low impact on the Confidentiality of data.

Weakness

The product stores a password in plaintext within resources such as memory or files.

Potential Mitigations

References