Vulnerability Description
Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high impact to the application's confidentiality, integrity, and availability.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://me.sap.com/notes/3634501
- https://me.sap.com/notes/3660659
- https://me.sap.com/notes/3670067
- https://url.sap/sapsecuritypatchday
FAQ
What is CVE-2025-42944?
CVE-2025-42944 is a vulnerability with a CVSS score of 10.0 (CRITICAL). Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserializa...
How severe is CVE-2025-42944?
CVE-2025-42944 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-42944?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.