Executive Summary

Informations
Name CVE-2025-31329 First vendor Publication 2025-05-13
Vendor Cve Last vendor Modification 2025-05-13

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N
Overall CVSS Score 6.2
Base Score 6.2 Environmental Score 6.2
impact SubScore 4 Temporal Score 6.2
Exploitabality Sub Score 1.7
 
Attack Vector Network Attack Complexity Low
Privileges Required High User Interaction Required
Scope Changed Confidentiality Impact High
Integrity Impact None Availability Impact None
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed by the victim, sensitive information such as user credentials is exposed. These credentials may then be used to gain unauthorized access to local or adjacent systems. This results in high impact to Confidentiality, with no significant effect on Integrity or Availability.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-31329

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-141 Failure to Sanitize Parameter/Argument Delimiters

Sources (Detail)

https://me.sap.com/notes/3577287
https://url.sap/sapsecuritypatchday
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2025-06-05 13:30:14
  • Multiple Updates
2025-05-27 02:57:02
  • First insertion