CVE-2025-42979 Details
Description
The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access to the user hive of this user�s windows registry could recreate the original password. There is no impact on integrity or availability of the application
A vulnerability exists in the GuiXT application, which is integrated with SAP GUI for Windows. The issue arises because the application employs obfuscation algorithms instead of secure symmetric ciphers to store the credentials of an RFC user on the client PC. This flaw allows an attacker with access to the user's Windows registry to reconstruct the original password, significantly compromising confidentiality. However, there is no impact on the integrity or availability of the application.
Users are advised to review and implement the latest SAP Security Notes. For guidance on accessing and applying these security updates, consult the SAP Security Notes FAQs or the SAP Security Patch Day Bulletin.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 8, 2025CISA-ADP
Assessed Jul 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://me.sap.com/notes/3607513 | [email protected] | Permission RequiredVendor |
| https://url.sap/sapsecuritypatchday | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-922 | Insecure Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SAP GuiXT | All versions |
CPE
Remediation
| |
| SAP GUI for Windows | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2025 | New CVE Received | [email protected] |
Volerion