Логотип exploitDog
bind:CVE-2025-42919
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-42919

Количество 3

Количество 3

nvd логотип

CVE-2025-42919

3 месяца назад

Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path components in the request, allowing unauthorized access to sensitive application metadata. This results in a partial compromise of the confidentiality of the information without affecting the integrity or availability of the application server.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-8q4r-fv9q-4gj4

3 месяца назад

Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path components in the request, allowing unauthorized access to sensitive application metadata. This results in a partial compromise of the confidentiality of the information without affecting the integrity or availability of the application server.

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2025-14455

3 месяца назад

Уязвимость сервера веб-приложений SAP NetWeaver Java Application Server, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-42919

Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path components in the request, allowing unauthorized access to sensitive application metadata. This results in a partial compromise of the confidentiality of the information without affecting the integrity or availability of the application server.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-8q4r-fv9q-4gj4

Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path components in the request, allowing unauthorized access to sensitive application metadata. This results in a partial compromise of the confidentiality of the information without affecting the integrity or availability of the application server.

CVSS3: 5.3
0%
Низкий
3 месяца назад
fstec логотип
BDU:2025-14455

Уязвимость сервера веб-приложений SAP NetWeaver Java Application Server, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
0%
Низкий
3 месяца назад

Уязвимостей на страницу