← Back to browse · API

CVE-2025-42944

Severity
CRITICAL
CVSS
10.0
EPSS
0.02893
Risk score
41.01
CISA KEV
No
PoC
No
Published
2025-09-09
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-27196, GHSA-F3F2-7MPX-VWJH
Products
SAP_SE:SAP Netweaver (RMI-P4) SERVERCORE 7.50
Sources
euvd EUVD-2025-27196

Description

Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high impact to the application's confidentiality, integrity, and availability.

References