Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27205 | SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and availability of the system. |
Tue, 09 Sep 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap java As Sap netweaver Sap netweaver Java Sap sap Netweaver |
|
| Vendors & Products |
Sap
Sap java As Sap netweaver Sap netweaver Java Sap sap Netweaver |
Tue, 09 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and availability of the system. | |
| Title | Insecure File Operations vulnerability in SAP NetWeaver AS Java (Deploy Web Service) | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-02-26T17:49:06.643Z
Reserved: 2025-04-16T13:25:32.384Z
Link: CVE-2025-42922
Updated: 2025-09-09T14:33:28.591Z
Status : Deferred
Published: 2025-09-09T02:15:40.480
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-42922
No data.
OpenCVE Enrichment
Updated: 2025-09-09T21:31:47Z
EUVD