XOR Marks the Flaw in SAP GUI
ID: 3e4beacc-1210-5232-bf71-053fdb009730
STIX ID: report--3e4beacc-1210-5232-bf71-053fdb009730
Feed Name: Dark Reading
SAP patched two medium-severity vulnerabilities in the SAP GUI input-history feature (CVE-2025-0055, CVE-2025-0056) that allow local disclosure of stored user inputs — including PII — because of weak XOR-based encryption in Windows and unencrypted Java serialization; a related unpatched flaw (CVE-2025-0059) in NetWeaver ABAP was also identified. Researchers warn attackers with local or network access (via HID injection, phishing, malware, or physical access) could exfiltrate history files, and recommend applying patches, disabling input history, and deleting existing history files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
