File Upload Vulnerability in SAP NetWeaver AS Java
CVE-2025-42922

9.9CRITICAL

Key Information:

Vendor

SAP

Vendor
CVE Published:
9 September 2025

What is CVE-2025-42922?

SAP NetWeaver AS Java contains a vulnerability that enables authenticated non-administrative users to exploit a service flaw for arbitrary file uploads. When a malicious file is uploaded and executed, it can jeopardize the system's confidentiality, integrity, and availability. This highlights the importance of ensuring robust access control measures and regular security assessments to safeguard sensitive data.

Affected Version(s)

SAP NetWeaver AS Java (Deploy Web Service) J2EE-APPS 7.50

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42922 : File Upload Vulnerability in SAP NetWeaver AS Java