PT-2026-2342 · Sap · Netweaver Application Server For Java
CVE-2026-0510
·
Publicado
2026-01-13
·
Atualizado
2026-01-13
CVSS v3.1
3.0
Baixa
| Vetor | AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NetWeaver Application Server for Java (NW AS Java) (affected versions not specified)
Description
The User Management Engine (UME) within the software uses an outdated cryptographic algorithm to encrypt User Mapping data. This could allow an attacker with high-privileged access to potentially reveal sensitive information under specific conditions. The impact on confidentiality is considered low, with no impact on integrity or availability.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Inadequate Encryption Strength
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Netweaver Application Server For Java