CVE-2025-0059 | SAP NetWeaver Application Server ABAP up to 9.14 GUI for HTML exposure of sensitive system information to an unauthorized control sphere (Nessus ID 270697 / WID-SEC-2026-0354)
A vulnerability categorized as problematic has been discovered in SAP NetWeaver Application Server ABAP up to 9.14. This impacts an unknown function of the component GUI for HTML. The manipulation results in exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is reported as CVE-2025-0059. The attack requires a local approach. No exploit exists.
Applying a patch is advised to resolve this issue.