CVE-2025-42926

MEDIUM

SAP NetWeaver Application Server Java - Unauthenticated Sensitive Information Exposure via Internal File Access

Title source: llm
STIX 2.1

Description

SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This vulnerability has a low impact on confidentiality and does not affect the integrity or availability of the server.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3619465

Scores

CVSS v3 5.3
EPSS 0.0009
EPSS Percentile 26.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
sap/netweaver_application_server_java 7.50
Published Sep 09, 2025
Tracked Since Feb 18, 2026