CVE-2025-42963
BaseFortify
Publication date: 2025-07-08
Last updated on: 2025-07-08
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | netweaver_application_server_for_java | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-502 | The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a critical security flaw in the SAP NetWeaver Application server for Java Log Viewer that allows authenticated administrator users to exploit unsafe Java object deserialization. Exploiting this flaw can give attackers full control over the operating system hosting the application.
How can this vulnerability impact me? :
If exploited, this vulnerability can lead to complete compromise of the affected system's operating system, allowing attackers to control the system fully. This severely impacts the confidentiality, integrity, and availability of both the application and the host environment.