CVE-2025-42883: Insecure File Operations vulnerability in SAP NetWeaver Application Server for ABAP (Migration Workbench)
Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an attacker with administrative privileges uploads files to the application server. An attacker could leverage this and upload a malicious file into the system. This results in a low impact on the integrity of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42883?
CVE-2025-42883 is considered to be a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-42883?
To fix CVE-2025-42883, ensure that your SAP NetWeaver Application Server for ABAP is updated to the latest patch.
What are the risks associated with CVE-2025-42883?
The risks associated with CVE-2025-42883 include unauthorized file uploads and potential system compromise due to lack of malware scanning.
Who is affected by CVE-2025-42883?
CVE-2025-42883 affects users of the SAP NetWeaver Application Server for ABAP with administrative privileges.
What should I do if I am vulnerable to CVE-2025-42883?
If you are vulnerable to CVE-2025-42883, it is critical to apply the software patch provided by SAP immediately.