CVE 4.3 MEDIUM

Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)_CVE-2025-42925

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could predict the identifiers by conducting a brute force search. By leveraging knowledge of several identifiers generated close to the same time, the attacker could determine a desired identifier which could enable them to access limited system information. This poses a low risk to confidentiality without impacting the integrity or availability of the service.

Basic Information

ID CVE-2025-42925
Source sap
Published Sep 9, 2025 at 02:09

Affected Product

Vendor SAP_SE
Product SAP NetWeaver AS Java (IIOP Service)
Version SERVERCORE 7.50
Affected Versions SAP_SE SAP NetWeaver AS Java (IIOP Service) SERVERCORE 7.50

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.