CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-31329: Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform

6.2 CVSS

Description

SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed by the victim, sensitive information such as user credentials is exposed. These credentials may then be used to gain unauthorized access to local or adjacent systems. This results in high impact to Confidentiality, with no significant effect on Integrity or Availability.

Classification

CVE ID: CVE-2025-31329

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.2

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N

Problem Types

CWE-141: Improper Neutralization of Parameter/Argument Delimiters

Affected Products

Vendor: SAP_SE

Product: SAP NetWeaver Application Server ABAP and ABAP Platform

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 9.25% (scored less or equal to compared to others)

EPSS Date: 2025-06-11 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2025-31329
https://me.sap.com/notes/3577287
https://url.sap/sapsecuritypatchday

Timeline