File Upload Vulnerability in SAP NetWeaver AS Java
CVE-2025-42922
9.9CRITICAL
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-42922?
SAP NetWeaver AS Java contains a vulnerability that enables authenticated non-administrative users to exploit a service flaw for arbitrary file uploads. When a malicious file is uploaded and executed, it can jeopardize the system's confidentiality, integrity, and availability. This highlights the importance of ensuring robust access control measures and regular security assessments to safeguard sensitive data.
Affected Version(s)
SAP NetWeaver AS Java (Deploy Web Service) J2EE-APPS 7.50