Insecure Java Deserialization in SAP NetWeaver XML Data Archiving Service
CVE-2025-42966

9.1CRITICAL

Key Information:

Vendor

SAP

Vendor
CVE Published:
8 July 2025

What is CVE-2025-42966?

The SAP NetWeaver XML Data Archiving Service contains an insecure Java deserialization vulnerability that can be exploited by authenticated attackers possessing administrative privileges. By sending a specially crafted serialized Java object, these attackers can compromise the confidentiality, integrity, and availability of the affected application. It is crucial to apply security measures to mitigate risks associated with this vulnerability.

Affected Version(s)

SAP NetWeaver (XML Data Archiving Service) J2EE-APPS 7.50

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42966 : Insecure Java Deserialization in SAP NetWeaver XML Data Archiving Service