CVE-2025-42966
- EPSS 0.07%
- Veröffentlicht 08.07.2025 00:36:13
- Zuletzt bearbeitet 08.07.2025 16:18:14
SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization vulnerability by sending a specially crafted serialized Java object. This could lead to high impact o...
CVE-2025-42964
- EPSS 0.07%
- Veröffentlicht 08.07.2025 00:35:53
- Zuletzt bearbeitet 08.07.2025 16:18:14
SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host...
CVE-2025-42963
- EPSS 0.07%
- Veröffentlicht 08.07.2025 00:35:45
- Zuletzt bearbeitet 08.07.2025 16:18:14
A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting a...
CVE-2025-42961
- EPSS 0.03%
- Veröffentlicht 08.07.2025 00:35:26
- Zuletzt bearbeitet 08.07.2025 16:18:14
Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privileges could exploit the insufficient validation of user permissions to access sensitive database tables. By leveraging overly perm...
CVE-2025-42959
- EPSS 0.16%
- Veröffentlicht 08.07.2025 00:35:03
- Zuletzt bearbeitet 08.07.2025 16:18:14
An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target sy...
CVE-2025-42953
- EPSS 0.06%
- Veröffentlicht 08.07.2025 00:34:41
- Zuletzt bearbeitet 08.07.2025 16:18:14
SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This could completely compromise the integrity and availability with no impact on confidentiality of ...
CVE-2025-42989
- EPSS 0.06%
- Veröffentlicht 10.06.2025 00:12:16
- Zuletzt bearbeitet 12.06.2025 16:06:39
RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact both integrity and availability of the applicatio...
CVE-2025-31325
- EPSS 0.09%
- Veröffentlicht 10.06.2025 00:10:30
- Zuletzt bearbeitet 12.06.2025 16:06:39
Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker could inject malicious JavaScript into a web page through an unprotected parameter. When a victim accesses the affected page, the s...
CVE-2025-42999
- EPSS 21.54%
- Veröffentlicht 13.05.2025 00:17:43
- Zuletzt bearbeitet 16.05.2025 19:44:49
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the hos...
CVE-2025-31329
- EPSS 0.06%
- Veröffentlicht 13.05.2025 00:16:51
- Zuletzt bearbeitet 13.05.2025 19:35:25
SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed b...