Additional hardening for a maximum-severity problem in SAP NetWeaver AS Java that could lead to arbitrary command execution is one of 13 new security concerns that SAP has released security solutions for.
The vulnerability has a CVSS score of 10.0 and is tagged as CVE-2025-42944. Some have referred to it as an instance of insecure deserialization.
According to a description of the flag on CVE.org, an unauthenticated attacker might use the RMI-P4 module to exploit the system by sending a malicious payload to an open port because of a deserialization vulnerability in SAP NetWeaver.
The confidentiality, integrity, and availability of the program may be seriously jeopardized if such untrusted Java objects were deserialized because this could result in unauthorized OS command execution.
SAP initially fixed the issue last month, but according to security firm Onapsis, the most recent update adds more protections against read more about New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
