CNNVD-202507-815 Information

CNNVD ID

CNNVD-202507-815

CVE-2025-42978

  • CNNVD Published: 2025-07-08

Description (Chinese)

SAP NetWeaver Application Server Java是德国思爱普(SAP)公司的一款提供了Java运行环境的应用程序服务器。该产品主要用于开发和运行Java EE应用程序。 SAP NetWeaver Application Server Java存在安全漏洞,该漏洞源于TLS连接主机名匹配不可靠,可能导致信息泄露。

Description (English)

SAP NetWeaver Application Server Java is an application server that provides the Java operating environment. The product is used mainly for the development and operation of Java EE applications. There is a security loophole in SAP NetWeaver Application Server Java, which stems from the unreliability of the TLS connection hostname, which may lead to the disclosure of information.

Hazard Level

Critical

Vulnerability Type

其他

Affected Vendor

思爱普

Published

2025-07-08

Last Modified

2026-02-24

References

https://me.sap.com/notes/3557179 https://url.sap/sapsecuritypatchday

Patch

https://support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2025.html

Share on: