CVE 5.3 MEDIUM

Information Disclosure vulnerability in SAP NetWeaver Application Server Java_CVE-2025-42919

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path components in the request, allowing unauthorized access to sensitive application metadata. This results in a partial compromise of the confidentiality of the information without affecting the integrity or availability of the application server.

Basic Information

ID CVE-2025-42919
Source sap
Published Nov 11, 2025 at 00:20

Affected Product

Vendor SAP_SE
Product SAP NetWeaver Application Server Java
Version ENGINEAPI 7.50
Affected Versions SAP_SE SAP NetWeaver Application Server Java ENGINEAPI 7.50
SAP_SE SAP NetWeaver Application Server Java EP-BASIS 7.50

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.