SAP NetWeaver AS Java Sensitive Information Vulnerability (January 2026)

low Nessus Plugin ID 288280

Synopsis

The remote SAP NetWeaver application server is affected by an Information Disclosure vulnerability.

Description

The version of SAP NetWeaver Application Server for Java detected on the remote host is affected by an Sensitive Information vulnerability as disclosed in the SAP Security Patch Day January 2026:

- The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially leading to partial disclosure of sensitive information. (CVE-2026-0510)

Note that Nessus has not tested for these issue but has instead relied only on the application's self-reported version number.

Solution

Apply the appropriate patch according to the vendor advisory.

See Also

http://www.nessus.org/u?02c0a10f

https://me.sap.com/notes/3593356

Plugin Details

Severity: Low

ID: 288280

File Name: sap_netweaver_as_java_jan_2026.nasl

Version: 1.1

Type: remote

Family: Web Servers

Published: 1/16/2026

Updated: 1/16/2026

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

CVSS v2

Risk Factor: Low

Base Score: 2.1

Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2026-0510

CVSS v3

Risk Factor: Low

Base Score: 3

Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N

Vulnerability Information

CPE: cpe:/a:sap:netweaver_application_server

Required KB Items: installed_sw/SAP Netweaver Application Server (AS), Settings/ParanoidReport

Patch Publication Date: 1/12/2026

Vulnerability Publication Date: 1/12/2026

Reference Information

CVE: CVE-2026-0510

IAVB: 2026-A-0031