Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an attacker with administrative privileges uploads files to the application server. An attacker could leverage this and upload a malicious file into the system. This results in a low impact on the integrity of the application.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 12 Nov 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap application Server
Sap netweaver
Sap netweaver Abap
Sap netweaver Abap Application Server
Sap netweaver Application Server
Vendors & Products Sap
Sap application Server
Sap netweaver
Sap netweaver Abap
Sap netweaver Abap Application Server
Sap netweaver Application Server

Tue, 11 Nov 2025 00:45:00 +0000

Type Values Removed Values Added
Description Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an attacker with administrative privileges uploads files to the application server. An attacker could leverage this and upload a malicious file into the system. This results in a low impact on the integrity of the application.
Title Insecure File Operations vulnerability in SAP NetWeaver Application Server for ABAP (Migration Workbench)
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-11-11T00:13:47.788Z

Reserved: 2025-04-16T13:25:19.826Z

Link: CVE-2025-42883

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-11T01:15:36.737

Modified: 2025-11-12T16:19:59.103

Link: CVE-2025-42883

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-12T12:47:43Z