Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2025-31329 | First vendor Publication | 2025-05-13 |
Vendor | Cve | Last vendor Modification | 2025-05-13 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N | |||
---|---|---|---|
Overall CVSS Score | 6.2 | ||
Base Score | 6.2 | Environmental Score | 6.2 |
impact SubScore | 4 | Temporal Score | 6.2 |
Exploitabality Sub Score | 1.7 | ||
Attack Vector | Network | Attack Complexity | Low |
Privileges Required | High | User Interaction | Required |
Scope | Changed | Confidentiality Impact | High |
Integrity Impact | None | Availability Impact | None |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : | |||
---|---|---|---|
Cvss Base Score | N/A | Attack Range | N/A |
Cvss Impact Score | N/A | Attack Complexity | N/A |
Cvss Expoit Score | N/A | Authentication | N/A |
Calculate full CVSS 2.0 Vectors scores |
Detail
SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed by the victim, sensitive information such as user credentials is exposed. These credentials may then be used to gain unauthorized access to local or adjacent systems. This results in high impact to Confidentiality, with no significant effect on Integrity or Availability. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-31329 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-141 | Failure to Sanitize Parameter/Argument Delimiters |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2025-06-05 13:30:14 |
|
2025-05-27 02:57:02 |
|