logo

XOR Marks the Flaw in SAP GUI

ID: 3e4beacc-1210-5232-bf71-053fdb009730

STIX ID: report--3e4beacc-1210-5232-bf71-053fdb009730

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2025-06-25

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

SAP patched two medium-severity vulnerabilities in the SAP GUI input-history feature (CVE-2025-0055, CVE-2025-0056) that allow local disclosure of stored user inputs — including PII — because of weak XOR-based encryption in Windows and unencrypted Java serialization; a related unpatched flaw (CVE-2025-0059) in NetWeaver ABAP was also identified. Researchers warn attackers with local or network access (via HID injection, phishing, malware, or physical access) could exfiltrate history files, and recommend applying patches, disabling input history, and deleting existing history files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.