Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-42926

Опубликовано: 09 сент. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This vulnerability has a low impact on confidentiality and does not affect the integrity or availability of the server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sap:netweaver_application_server_java:7.50:*:*:*:*:*:*:*

EPSS

Процентиль: 26%
0.00089
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 5.3
github
5 месяцев назад

SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This vulnerability has a low impact on confidentiality and does not affect the integrity or availability of the server.

CVSS3: 5.3
fstec
10 месяцев назад

Уязвимость сервера приложений SAP NetWeaver Application Server Java, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить доступ на чтение данных

EPSS

Процентиль: 26%
0.00089
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-306