PT-2025-1184 · Sap · Sap Netweaver Application Server For Abap/Abap Platform

Published

2025-01-14

·

Updated

2025-10-24

·

CVE-2025-0053

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server for ABAP and ABAP Platform (affected versions not specified)
Description The issue is related to information disclosure in error messages. An attacker, acting remotely, could gain unauthorized access to protected information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration, which may have a limited impact on the confidentiality of the application and could be leveraged to facilitate further attacks or exploits.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-00467
CVE-2025-0053

Affected Products

Sap Netweaver Application Server For Abap/Abap Platform