Remote Code Execution in SAP NetWeaver Xcelsius
CVE-2025-42874
7.9HIGH
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-42874?
A vulnerability in SAP NetWeaver's remote service for Xcelsius allows attackers with network access and elevated privileges to execute arbitrary code. This arises from insufficient input validation and improper handling of remote method calls. The exploitation of this vulnerability does not require user interaction, which may lead to potential service disruption or unauthorized system control, significantly impacting integrity and availability.
Affected Version(s)
SAP NetWeaver (remote service for Xcelsius) BI-BASE-E 7.50
SAP NetWeaver (remote service for Xcelsius) BI-BASE-B 7.50
SAP NetWeaver (remote service for Xcelsius) BI-IBC 7.50