CVE-2025-31329
SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed by the victim, sensitive information such as user credentials is exposed. These credentials may then be used to gain unauthorized access to local or adjacent systems. This results in high impact to Confidentiality, with no significant effect on Integrity or Availability.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N
- EPSS probability
- 0.34%
- CWE
- CWE-141
- Published
- 2025-05-13
- Last modified
- 2026-03-12
Affected products
- SAP_SE SAP NetWeaver Application Server ABAP and ABAP Platform
- SAP_SE SAP NetWeaver Application Server ABAP and ABAP Platform
- SAP_SE SAP NetWeaver Application Server ABAP and ABAP Platform
- SAP_SE SAP NetWeaver Application Server ABAP and ABAP Platform
- SAP_SE SAP NetWeaver Application Server ABAP and ABAP Platform
- SAP_SE SAP NetWeaver Application Server ABAP and ABAP Platform
- SAP_SE SAP NetWeaver Application Server ABAP and ABAP Platform
- SAP_SE SAP NetWeaver Application Server ABAP and ABAP Platform
Weakness type
Related vulnerabilities
- CVE-2026-66323 — Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2026-19594 — Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege Escalation
- CVE-2026-20200 — Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability
- CVE-2026-56813 — Cookie attribute injection in Plug.Conn.Cookies.encode/2
- CVE-2025-20338 — A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker...
- CVE-2024-0840 — Grandstream UCM Series IP PBX HTTP Parameter Injection
- CVE-2022-41665 — A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.10),...
- CVE-2022-29873 — A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not...