Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path components in the request, allowing unauthorized access to sensitive application metadata. This results in a partial compromise of the confidentiality of the information without affecting the integrity or availability of the application server.
History

Wed, 12 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap netweaver Application Server Java
Vendors & Products Sap
Sap netweaver Application Server Java

Tue, 11 Nov 2025 00:45:00 +0000

Type Values Removed Values Added
Description Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path components in the request, allowing unauthorized access to sensitive application metadata. This results in a partial compromise of the confidentiality of the information without affecting the integrity or availability of the application server.
Title Information Disclosure vulnerability in SAP NetWeaver Application Server Java
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-11-11T00:20:18.388Z

Updated: 2025-11-12T20:09:44.146Z

Reserved: 2025-04-16T13:25:30.253Z

Link: CVE-2025-42919

cve-icon Vulnrichment

Updated: 2025-11-12T17:31:08.361Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-11T01:15:38.937

Modified: 2025-11-12T16:19:59.103

Link: CVE-2025-42919

cve-icon Redhat

No data.