Remote Code Execution in SAP NetWeaver Xcelsius
CVE-2025-42874
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-42874?
A vulnerability in SAP NetWeaver's remote service for Xcelsius allows attackers with network access and elevated privileges to execute arbitrary code. This arises from insufficient input validation and improper handling of remote method calls. The exploitation of this vulnerability does not require user interaction, which may lead to potential service disruption or unauthorized system control, significantly impacting integrity and availability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP NetWeaver (remote service for Xcelsius) BI-BASE-E 7.50
SAP NetWeaver (remote service for Xcelsius) BI-BASE-B 7.50
SAP NetWeaver (remote service for Xcelsius) BI-IBC 7.50
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved