PT-2025-46225 · Sap · Sap Netweaver Enterprise Portal

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2025-42884

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Enterprise Portal (affected versions not specified)
Description An unauthenticated attacker can inject JNDI environment properties or provide a URL during JNDI lookup operations. This could allow access to an unintended JNDI provider, potentially leading to information disclosure or modification on the server. The issue does not impact system availability. The attack involves manipulating JNDI (Java Naming and Directory Interface) lookups, a Java API for discovering data and objects.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-14453
CVE-2025-42884

Affected Products

Sap Netweaver Enterprise Portal