Remote Code Execution in SAP NetWeaver Xcelsius
CVE-2025-42874

7.9HIGH

Key Information:

Vendor

SAP

Vendor
CVE Published:
9 December 2025

What is CVE-2025-42874?

A vulnerability in SAP NetWeaver's remote service for Xcelsius allows attackers with network access and elevated privileges to execute arbitrary code. This arises from insufficient input validation and improper handling of remote method calls. The exploitation of this vulnerability does not require user interaction, which may lead to potential service disruption or unauthorized system control, significantly impacting integrity and availability.

Affected Version(s)

SAP NetWeaver (remote service for Xcelsius) BI-BASE-E 7.50

SAP NetWeaver (remote service for Xcelsius) BI-BASE-B 7.50

SAP NetWeaver (remote service for Xcelsius) BI-IBC 7.50

References

CVSS V3.1

Score:
7.9
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42874 : Remote Code Execution in SAP NetWeaver Xcelsius