PT-2026-2342 · Sap · Netweaver Application Server For Java
Published
2026-01-13
·
Updated
2026-01-13
·
CVE-2026-0510
CVSS v3.1
3.0
Low
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NetWeaver Application Server for Java (NW AS Java) (affected versions not specified)
Description
The User Management Engine (UME) within the software uses an outdated cryptographic algorithm to encrypt User Mapping data. This could allow an attacker with high-privileged access to potentially reveal sensitive information under specific conditions. The impact on confidentiality is considered low, with no impact on integrity or availability.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netweaver Application Server For Java