The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially leading to partial disclosure of sensitive information.This has low impact on confidentiality with no impact on integrity and availability of the application.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap java As |
|
| Vendors & Products |
Sap
Sap java As |
Tue, 13 Jan 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially leading to partial disclosure of sensitive information.This has low impact on confidentiality with no impact on integrity and availability of the application. | |
| Title | Obsolete Encryption Algorithm Used in NW AS Java UME User Mapping | |
| Weaknesses | CWE-326 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-01-13T18:26:48.509Z
Reserved: 2025-12-09T22:06:49.250Z
Link: CVE-2026-0510
Updated: 2026-01-13T18:19:19.054Z
Status : Awaiting Analysis
Published: 2026-01-13T02:15:53.597
Modified: 2026-01-13T14:03:18.990
Link: CVE-2026-0510
No data.
OpenCVE Enrichment
Updated: 2026-01-13T09:27:06Z