The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not reliably match the hostname that is used for the connection against the wildcard hostname defined in the received certificate of remote TLS server. This might lead to the outbound connection being established to a possibly malicious remote TLS server and hence disclose information. Integrity and Availability are not impacted.
History

Tue, 08 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Jul 2025 00:45:00 +0000

Type Values Removed Values Added
Description The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not reliably match the hostname that is used for the connection against the wildcard hostname defined in the received certificate of remote TLS server. This might lead to the outbound connection being established to a possibly malicious remote TLS server and hence disclose information. Integrity and Availability are not impacted.
Title Insufficiently Secure Hostname Verification for Outbound TLS Connections in SAP NetWeaver Application Server Java
Weaknesses CWE-940
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-07-08T00:37:44.388Z

Updated: 2025-07-08T18:14:00.450Z

Reserved: 2025-04-16T13:25:45.231Z

Link: CVE-2025-42978

cve-icon Vulnrichment

Updated: 2025-07-08T18:11:39.282Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-08T01:15:24.930

Modified: 2025-07-08T16:18:14.207

Link: CVE-2025-42978

cve-icon Redhat

No data.