PT-2025-36556 · Sap · Sap Netweaver Application Server Java

Published

2025-04-16

·

Updated

2025-09-09

·

CVE-2025-42926

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SAP NetWeaver Application Server Java (affected versions not specified)
Description: SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application. Successful exploitation could allow an unauthenticated attacker to access these files and gather sensitive information about the system. This issue has a low impact on confidentiality and does not affect the integrity or availability of the server.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2026-00022
CVE-2025-42926

Affected Products

Sap Netweaver Application Server Java