Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27196 | Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high impact to the application's confidentiality, integrity, and availability. |
Wed, 12 Nov 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 14 Oct 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 09 Sep 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap netweaver Sap sap Netweaver |
|
| Vendors & Products |
Sap
Sap netweaver Sap sap Netweaver |
Tue, 09 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high impact to the application's confidentiality, integrity, and availability. | |
| Title | Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4) | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-02-26T17:49:05.927Z
Reserved: 2025-04-16T13:25:37.187Z
Link: CVE-2025-42944
Updated: 2025-09-09T13:25:08.450Z
Status : Deferred
Published: 2025-09-09T02:15:42.173
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-42944
No data.
OpenCVE Enrichment
Updated: 2025-09-09T21:31:44Z
EUVD