First published: Tue Feb 11 2025(Updated: )
SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This information should ideally be restricted to customer administrators, even though they may not need it. These XML files are not entirely SAP-internal as they are deployed with the server. In such a scenario, sensitive information could be exposed without compromising its integrity or availability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS JAVA |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24869 has been rated as a medium severity vulnerability.
To fix CVE-2025-24869, it is recommended to apply the latest security patches provided by SAP for the NetWeaver Application Server Java.
CVE-2025-24869 can expose information about deployed server components, including their XML definitions.
CVE-2025-24869 affects users of the SAP NetWeaver Application Server Java.
Currently, no specific workarounds are advised for CVE-2025-24869 other than applying the appropriate SAP patches.