VDB

CVE-2026-0510

CVE-2026-0510 PUBLISHED CVSS 3 LOW

The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially leading to partial disclosure of sensitive information.This has low impact on confidentiality with no impact on integrity and availability of the application.

EPSS 0.02% · 5.5th percentile

Risk Scores

CVSS 3.1
3
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
EPSS Score
0.02%
5.5th percentile

Affected Products

VendorProductVersions
SAP_SENW AS Java UME User MappingSERVERCORE 7.50, UMEADMIN 7.50, *

Timeline

  • Jan 13, 2026 EPSS Score
  • Jan 13, 2026 CVE Published
  • Jan 13, 2026 CVE Updated
  • Jan 13, 2026 PoC Published
  • Jan 16, 2026 EPSS Score
  • Jan 19, 2026 EPSS Score
  • Jan 22, 2026 EPSS Score
  • Jan 25, 2026 EPSS Score
  • Jan 28, 2026 EPSS Score
  • Jan 31, 2026 EPSS Score
  • Feb 3, 2026 EPSS Score
  • Feb 6, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›