Information Disclosure Vulnerability in SAP NetWeaver
CVE-2025-31329

6.2MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
13 May 2025

What is CVE-2025-31329?

SAP NetWeaver is susceptible to an Information Disclosure vulnerability that arises from the injection of malicious commands into user configuration settings. If an attacker with administrative access improperly manipulates these settings, they can expose sensitive information, including user credentials. This information is vulnerable to exploitation, enabling unauthorized access to local or associated systems while significantly compromising confidentiality.

Affected Version(s)

SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 700

SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 701

SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 702

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.
CVE-2025-31329 : Information Disclosure Vulnerability in SAP NetWeaver