CVE-2025-42922: Insecure File Operations vulnerability in SAP NetWeaver AS Java (Deploy Web Service)
SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42922?
CVE-2025-42922 is considered a critical vulnerability due to its potential to allow full compromise of system confidentiality, integrity, and availability.
How do I fix CVE-2025-42922?
To fix CVE-2025-42922, apply the latest security patches provided by SAP for NetWeaver AS Java.
Who is affected by CVE-2025-42922?
Anyone using SAP NetWeaver AS Java is potentially affected by CVE-2025-42922 if they allow non-administrative user access.
What is the impact of exploiting CVE-2025-42922?
Exploiting CVE-2025-42922 can lead to unauthorized file uploads that may compromise the entire system.
Can CVE-2025-42922 be exploited remotely?
CVE-2025-42922 requires an authenticated non-administrative user, making it less likely to be exploited remotely without such access.