CVE-2025-42944: Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)

Published Sep 9, 2025
·
Updated

Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high impact to the application's confidentiality, integrity, and availability.

Affected Software

1 affected component
SAP NetWeaver

Event History

Dec 10, 2024
News Published
08:48 PM
Jul 8, 2025
News Published
11:01 PM
Sep 9, 2025
CVE Published
via MITRE·02:11 AM
Data Sourced
via MITRE·02:11 AM
DescriptionSeverity
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
News Published
via BleepingComputer·01:18 PM
News Published
via BleepingComputer·01:19 PM
Sep 10, 2025
News Published
via The Register·03:31 AM
News Published
via The Register·03:36 AM
Nov 11, 2025
News Published
via BleepingComputer·03:38 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-42944?

CVE-2025-42944 has a high severity due to its potential for arbitrary OS command execution through deserialization vulnerabilities.

2

How do I fix CVE-2025-42944?

To fix CVE-2025-42944, update your SAP NetWeaver to the latest version that addresses this vulnerability.

3

What impact does CVE-2025-42944 have on SAP NetWeaver?

CVE-2025-42944 allows unauthenticated attackers to execute arbitrary commands on the operating system through the RMI-P4 module.

4

What are the signs of exploitation of CVE-2025-42944?

Signs of exploitation may include unexpected behaviors, increased network traffic to open ports, or unusual system performance.

5

Is CVE-2025-42944 associated with a specific version of SAP NetWeaver?

CVE-2025-42944 affects SAP NetWeaver and requires vigilance across all installations utilizing the vulnerable RMI-P4 module.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203