Cyber Resilience

CVE-2025-42926

Access Control in Sap Netweaver Application Server Java 7.50

Published
09 September 2025
Modified
23 October 2025
Patch / advisory
CVSS Score v3.1 5.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score 0.0028 20th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2025-42926 is a medium-severity Missing Authentication for Critical Function (CWE-306) vulnerability in Sap Netweaver Application Server Java. Its CVSS base score is 5.3 (Medium).

Operationally, ranked at the 20th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and IA-2 (Identification and Authentication (Organizational Users)) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This…

more

vulnerability has a low impact on confidentiality and does not affect the integrity or availability of the server.

CWE(s)

Related Threats

CVEs Like This One

CVE-2020-6287Same product: Sap Netweaver Application Server Java
CVE-2010-5326Same product: Sap Netweaver Application Server Java
CVE-2023-24526Same product: Sap Netweaver Application Server Java
CVE-2017-12637Same product: Sap Netweaver Application Server Java
CVE-2024-22126Same product: Sap Netweaver Application Server Java
CVE-2016-2388Same product: Sap Netweaver Application Server Java
CVE-2024-22127Same product: Sap Netweaver Application Server Java
CVE-2023-42480Same product: Sap Netweaver Application Server Java
CVE-2016-9563Same product: Sap Netweaver Application Server Java
CVE-2016-2386Same product: Sap Netweaver Application Server Java

Affected Assets

sap
netweaver application server java
7.50

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
  • AC-3 Access Enforcement
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-8 Identification and Authentication (Non-organizational Users)
Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)
  • 6 hardening rules · 3 OS baselines
Validate
Prove the fix (OWASP ASVS)
  • V6.2.3
  • V6.4.4
  • V10.4.16
  • V12.1.3

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly enforces authentication requirements before allowing access to internal application files, blocking the unauthenticated access path described in CVE-2025-42926.

prevent

Requires identification and authentication of organizational users prior to granting access to system resources, directly mitigating the missing authentication weakness (CWE-306).

prevent

Mandates identification and authentication for non-organizational users before access, preventing the unauthenticated attacker exploitation path in this SAP NetWeaver vulnerability.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.AA-03 full match
prevents

Directly requires authentication of users/services/hardware, which eliminates missing authentication for critical functions.

PR.AA-01 partial match
prevents

Managing identities and credentials is a prerequisite for authentication but does not itself enforce it on critical functions.

PR.AA-05 partial match
prevents

Defining and enforcing authorizations assumes prior authentication and therefore only partially mitigates the absence of authentication.

PR.IR-01 partial match
prevents

Protecting networks from unauthorized access can be undermined by missing authentication but does not address the root authentication gap.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

prevents

The control explicitly calls for authentication before any critical function is reached, eliminating the possibility of bypassing authentication for high-value operations.

prevents

Mandating authentication requirements for critical functions at the requirements-gathering stage ensures that essential operations are not left unprotected by missing login or verification mechanisms.

mitigates

Mandating authentication for network services and critical functions stops attackers from invoking sensitive operations without credentials, closing gaps where authentication is absent for important capabilities.

prevents

Security engineering principles insist on authentication and authorization for every critical function, eliminating entry points that lack any access control mechanism.

none

Requiring strong authentication and access-privilege enablement for remote connections ensures that critical functions cannot be invoked without proper verification, closing a gap that would otherwise allow unauthenticated use.

none

Mandatory use of access cards, biometrics, or two-factor authentication ensures that critical physical areas cannot be entered without proper authentication.

References