CVE-2025-42925
Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could predict the identifiers by conducting a brute force search. By leveraging knowledge of several identifiers generated close to the same time, the attacker could determine a desired identifier which could enable them to access limited system information. This poses a low risk to confidentiality without impacting the integrity or availability of the service.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.23%
- CWE
- CWE-341
- Published
- 2025-09-09
- Last modified
- 2026-03-13
Affected products
- SAP_SE SAP NetWeaver AS Java (IIOP Service)
Weakness type
Related vulnerabilities
- CVE-2026-19565 — Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey
- CVE-2026-15571 — Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client
- CVE-2026-42365 — GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability
- CVE-2025-40780 — Cache poisoning due to weak PRNG
- CVE-2024-10141 — jsbroks COCO Annotator Session predictable state
- CVE-2023-49259 — Bruteforcing authentication cookie for a given user
- CVE-2021-4277 — fredsmith utils Filename screenshot_sync predictable state
- CVE-2020-5365 — Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The...