SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization vulnerability by sending a specially crafted serialized Java object. This could lead to high impact on confidentiality, integrity, and availability of the application.
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00044}

epss

{'score': 0.00058}


Tue, 08 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Jul 2025 00:45:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization vulnerability by sending a specially crafted serialized Java object. This could lead to high impact on confidentiality, integrity, and availability of the application.
Title Insecure Deserialization vulnerability in SAP NetWeaver (XML Data Archiving Service)
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-07-08T00:36:13.153Z

Updated: 2025-07-09T04:02:09.931Z

Reserved: 2025-04-16T13:25:42.158Z

Link: CVE-2025-42966

cve-icon Vulnrichment

Updated: 2025-07-08T14:29:27.616Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-08T01:15:23.630

Modified: 2025-07-08T16:18:14.207

Link: CVE-2025-42966

cve-icon Redhat

No data.