Information Disclosure in SAP NetWeaver Application Server Java
CVE-2025-42919

5.3MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 November 2025

What is CVE-2025-42919?

An Information Disclosure vulnerability has been identified in SAP NetWeaver Application Server Java, allowing unauthenticated attackers to exploit the server by manipulating URLs. By inserting arbitrary path components into requests, attackers can gain access to sensitive internal metadata files, leading to unauthorized visibility of application information. This vulnerability raises significant concerns regarding the confidentiality of sensitive data while the integrity and availability of the application server remain intact. It is crucial for users of affected versions to apply the necessary security patches to mitigate this risk.

Affected Version(s)

SAP NetWeaver Application Server Java ENGINEAPI 7.50

SAP NetWeaver Application Server Java EP-BASIS 7.50

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.