Remote Code Execution in SAP NetWeaver Xcelsius
CVE-2025-42874
7.9HIGH
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-42874?
A vulnerability in SAP NetWeaver's remote service for Xcelsius allows attackers with network access and elevated privileges to execute arbitrary code. This arises from insufficient input validation and improper handling of remote method calls. The exploitation of this vulnerability does not require user interaction, which may lead to potential service disruption or unauthorized system control, significantly impacting integrity and availability.
Affected Version(s)
SAP NetWeaver (remote service for Xcelsius) BI-BASE-E 7.50
SAP NetWeaver (remote service for Xcelsius) BI-BASE-B 7.50
SAP NetWeaver (remote service for Xcelsius) BI-IBC 7.50
References
CVSS V3.1
Score:
7.9
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved