New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login
Additional hardening for a maximum-severity problem in SAP NetWeaver AS Java that could lead to arbitrary command execution is one of 13 new security concerns that SAP has released security solutions for.
The vulnerability has a CVSS score of 10.0 and is tagged as CVE-2025-42944. Some have referred to it as an instance of insecure deserialization.
According to a description of the flag on CVE.org, an unauthenticated attacker might use the RMI-P4 module to exploit the system by sending a malicious payload to an open port because of a deserialization vulnerability in SAP NetWeaver.
The confidentiality, integrity, and availability of the program may be seriously jeopardized if such untrusted Java objects were deserialized because this could result in unauthorized OS command executio...

