CVE-2025-42926
MEDIUMSAP NetWeaver Application Server Java - Unauthenticated Sensitive Information Exposure via Internal File Access
Title source: llmDescription
SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This vulnerability has a low impact on confidentiality and does not affect the integrity or availability of the server.
References (2)
Core 2
Core References
Permissions Required
https://me.sap.com/notes/3619465
Scores
CVSS v3
5.3
EPSS
0.0009
EPSS Percentile
26.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (1)
sap/netweaver_application_server_java
7.50
Published
Sep 09, 2025
Tracked Since
Feb 18, 2026