Information Disclosure Vulnerability in SAP NetWeaver
CVE-2025-31329
6.2MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 May 2025
What is CVE-2025-31329?
SAP NetWeaver is susceptible to an Information Disclosure vulnerability that arises from the injection of malicious commands into user configuration settings. If an attacker with administrative access improperly manipulates these settings, they can expose sensitive information, including user credentials. This information is vulnerable to exploitation, enabling unauthorized access to local or associated systems while significantly compromising confidentiality.
Affected Version(s)
SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 700
SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 701
SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 702
References
CVSS V3.1
Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published