CVE-2025-42926

Published Sep 9, 2025

Last updated 4 months ago

Overview

Description
SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This vulnerability has a low impact on confidentiality and does not affect the integrity or availability of the server.
Source
cna@sap.com
NVD status
Analyzed
Products
netweaver_application_server_java

Risk scores

CVSS 3.1

Type
Primary
Base score
5.3
Impact score
1.4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity
MEDIUM

Weaknesses

cna@sap.com
CWE-306

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.