CVE-2025-42884
BaseFortify
Publication date: 2025-11-11
Last updated on: 2025-11-12
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | netweaver_enterprise_portal | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-943 | The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL used during JNDI lookup operations. This enables the attacker to access an unintended JNDI provider, potentially leading to disclosure or modification of information about the server. There is no impact on availability.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure or modification of server information, which may compromise the confidentiality and integrity of data. However, it does not affect the availability of the system.