Critical Alert 1 Active Exploit Detected Today

CVE-2026-9082 Drupal Core SQL Injection Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

← Back to CVE List

CVE-2025-42884NVD

Description

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL used during JNDI lookup operations, enabling access to an unintended JNDI provider.οΏ½This could further lead to disclosure or modification of information about the server. There is no impact on availability.
Severity Level
MEDIUM (6.5)
Published Date
11/11/2025
Last Modified
11/11/2025
Exploitation Status
UNKNOWN