SAP Financial Services Claims Management User Enumeration Vulnerability in RFC Function ICL_USER_GET_NAME_AND_ADDRESS

Vulnerability

A vulnerability exists in the SAP Financial Services Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS, allowing for user enumeration and potential disclosure of personal data. This issue arises from discrepancies in response data, leading to a low impact on confidentiality, with no effect on integrity or availability.

Impact

Exploitation of this vulnerability could result in unauthorized user enumeration and the potential disclosure of personal data, according to SAP.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, where all Security Notes are available. It is recommended to implement these security corrections as a priority.

Added: Oct 14, 2025, 1:23 AM
Updated: Oct 14, 2025, 1:23 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.