SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0005}

epss

{'score': 0.00065}


Tue, 08 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Jul 2025 00:45:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
Title Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-07-09T04:02:07.791Z

Reserved: 2025-04-16T13:25:42.157Z

Link: CVE-2025-42964

cve-icon Vulnrichment

Updated: 2025-07-08T14:30:09.964Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-08T01:15:23.240

Modified: 2025-07-08T16:18:14.207

Link: CVE-2025-42964

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.