CVE Explorer
CVE-2026-0510
The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially leading to partial disclosure of sensitive information.This has low impact on confidentiality with no impact on integrity and availability of the application.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"NW AS Java UME User Mapping","vendor":"SAP_SE","versions":[{"status":"affected","version":"ENGINEAPI 7.50"},{"status":"affected","version":"SERVERCORE 7.50"},{"status":"affected","version":"UMEADMIN 7.50"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c7bf51517f422ff70671f9314ac72a04430baa1c1dbd8b673170fa1e4349039e · sha256:6f80fb73dc29988e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c7bf51517f422ff70671f9314ac72a04430baa1c1dbd8b673170fa1e4349039e · sha256:6f80fb73dc29988e… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-326","description":"CWE-326: Inadequate Encryption Strength","lang":"eng","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c7bf51517f422ff70671f9314ac72a04430baa1c1dbd8b673170fa1e4349039e · sha256:6f80fb73dc29988e… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://me.sap.com/notes/3593356"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c7bf51517f422ff70671f9314ac72a04430baa1c1dbd8b673170fa1e4349039e · sha256:6f80fb73dc29988e… · /containers/cna/references/0
{"url":"https://url.sap/sapsecuritypatchday"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c7bf51517f422ff70671f9314ac72a04430baa1c1dbd8b673170fa1e4349039e · sha256:6f80fb73dc29988e… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.