Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cv7h-78v9-r3jf

Опубликовано: 13 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3

Описание

The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially leading to partial disclosure of sensitive information.This has low impact on confidentiality with no impact on integrity and availability of the application.

The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially leading to partial disclosure of sensitive information.This has low impact on confidentiality with no impact on integrity and availability of the application.

EPSS

Процентиль: 2%
0.00014
Низкий

3 Low

CVSS3

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 3
nvd
25 дней назад

The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially leading to partial disclosure of sensitive information.This has low impact on confidentiality with no impact on integrity and availability of the application.

CVSS3: 3
fstec
25 дней назад

Уязвимость компонента User Management Engine (UME) сервера веб-приложений SAP NetWeaver Java Application Server, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 2%
0.00014
Низкий

3 Low

CVSS3

Дефекты

CWE-326