SAP NetWeaver Application Server Java TLS Hostname Verification Vulnerability

Vulnerability

A vulnerability exists in the component responsible for outbound TLS connections in SAP NetWeaver Application Server Java. This vulnerability arises because the hostname used for the connection is not reliably matched against the wildcard hostname defined in the certificate received from the remote TLS server. As a result, an outbound connection could be established to a potentially malicious remote TLS server, leading to information disclosure. This issue affects several different versions and ranges.

Impact

Exploitation of this vulnerability could result in information disclosure by allowing connections to malicious remote TLS servers.

Remediation

Users are advised to review and implement the SAP Security Note related to this vulnerability. This can be done through the SAP for Me platform, where all security notes are available. For details on the next SAP Security Patch Day, refer to the SAP Security Patch Day calendar.

Added: Jul 8, 2025, 1:31 AM
Updated: Jul 8, 2025, 1:31 AM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
2.5
exploitability
5.2
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.