SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed by the victim, sensitive information such as user credentials is exposed. These credentials may then be used to gain unauthorized access to local or adjacent systems. This results in high impact to Confidentiality, with no significant effect on Integrity or Availability.
History

Tue, 13 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 May 2025 00:45:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed by the victim, sensitive information such as user credentials is exposed. These credentials may then be used to gain unauthorized access to local or adjacent systems. This results in high impact to Confidentiality, with no significant effect on Integrity or Availability.
Title Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Weaknesses CWE-141
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-05-13T00:16:51.190Z

Updated: 2025-05-13T13:55:58.324Z

Reserved: 2025-03-27T23:02:06.906Z

Link: CVE-2025-31329

cve-icon Vulnrichment

Updated: 2025-05-13T13:55:55.530Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-13T01:15:48.137

Modified: 2025-05-13T19:35:25.503

Link: CVE-2025-31329

cve-icon Redhat

No data.