A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting attackers complete control over the affected system. This results in a severe impact on the confidentiality, integrity, and availability of the application and host environment.
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00044}

epss

{'score': 0.00058}


Tue, 08 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Jul 2025 00:45:00 +0000

Type Values Removed Values Added
Description A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting attackers complete control over the affected system. This results in a severe impact on the confidentiality, integrity, and availability of the application and host environment.
Title Insecure Deserialization in SAP NetWeaver Application Server for Java (Log Viewer )
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-07-08T00:35:45.105Z

Updated: 2025-07-09T04:02:08.834Z

Reserved: 2025-04-16T13:25:42.157Z

Link: CVE-2025-42963

cve-icon Vulnrichment

Updated: 2025-07-08T14:30:17.013Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-08T01:15:23.093

Modified: 2025-07-08T16:18:14.207

Link: CVE-2025-42963

cve-icon Redhat

No data.