← Back

CVE-2025-42926

nvd nist
Published: Sep 9, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This vulnerability has a low impact on confidentiality and does not affect the integrity or availability of the server.

Affected (1)

1 product
Netweaver Application Server Java
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.50

References (2)

Source: cna@sap.com
Permissions Required
Source: cna@sap.com
Patch

Timeline

No history available yet.