CVE-2025-42928: Deserialization Vulnerability in SAP jConnect - SDK for ASE
Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch remote code execution. The system may be vulnerable when specially crafted input is used to exploit the vulnerability resulting in high impact on confidentiality, integrity and availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42928?
CVE-2025-42928 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-42928?
To mitigate CVE-2025-42928, apply the latest security patches provided by SAP for jConnect.
Who is affected by CVE-2025-42928?
CVE-2025-42928 affects users and applications utilizing SAP jConnect under specific conditions.
What are the potential impacts of CVE-2025-42928?
The exploitation of CVE-2025-42928 can lead to unauthorized access and compromise of confidential data.
When was CVE-2025-42928 reported?
CVE-2025-42928 was reported in 2025, highlighting an urgent need for attention and remediation.