CVE-2025-42874
- EPSS 0.08%
- Veröffentlicht 09.12.2025 02:14:19
- Zuletzt bearbeitet 09.12.2025 18:36:53
SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrary code on the affected system due to insufficient input validation and improper handling of remote method calls. Exploitation does...
CVE-2025-42872
- EPSS 0.06%
- Veröffentlicht 09.12.2025 02:13:55
- Zuletzt bearbeitet 09.12.2025 18:36:53
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tok...
CVE-2025-42919
- EPSS 0.16%
- Veröffentlicht 11.11.2025 00:20:18
- Zuletzt bearbeitet 12.11.2025 16:19:59
Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path componen...
CVE-2025-42884
- EPSS 0.13%
- Veröffentlicht 11.11.2025 00:14:02
- Zuletzt bearbeitet 12.11.2025 16:19:59
SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL used during JNDI lookup operations, enabling access to an unintended JNDI provider.�This could further lead to disclosure or modifi...
CVE-2025-42882
- EPSS 0.03%
- Veröffentlicht 11.11.2025 00:13:33
- Zuletzt bearbeitet 12.11.2025 16:19:59
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module in ABAP to retrieve restricted technical information from the system. This dis...
CVE-2025-42908
- EPSS 0.02%
- Veröffentlicht 14.10.2025 00:18:04
- Zuletzt bearbeitet 14.10.2025 19:36:29
Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session manager, bypassing the first transaction screen and the associated a...
CVE-2025-42902
- EPSS 0.06%
- Veröffentlicht 14.10.2025 00:17:32
- Zuletzt bearbeitet 14.10.2025 19:36:29
Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads to a dereference of NULL which ...
- EPSS 0.02%
- Veröffentlicht 09.09.2025 02:15:42
- Zuletzt bearbeitet 12.11.2025 19:15:36
Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to ...
CVE-2025-42927
- EPSS 0.02%
- Veröffentlicht 09.09.2025 02:15:41
- Zuletzt bearbeitet 09.09.2025 16:28:43
SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library would allow user with high system privileges to access and ...
CVE-2025-42926
- EPSS 0.08%
- Veröffentlicht 09.09.2025 02:15:41
- Zuletzt bearbeitet 23.10.2025 12:43:32
SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gathe...