← Back to browse · API

CVE-2025-42922

Severity
CRITICAL
CVSS
9.9
EPSS
0.007
Risk score
39.84
CISA KEV
No
PoC
No
Published
2025-09-09
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-27205, GHSA-4967-53PF-WQ6X
Products
SAP_SE:SAP NetWeaver AS Java (Deploy Web Service) J2EE-APPS 7.50
Sources
euvd EUVD-2025-27205

Description

SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and availability of the system.

References