CVE-2025-42944: Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)
Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high impact to the application's confidentiality, integrity, and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42944?
CVE-2025-42944 has a high severity due to its potential for arbitrary OS command execution through deserialization vulnerabilities.
How do I fix CVE-2025-42944?
To fix CVE-2025-42944, update your SAP NetWeaver to the latest version that addresses this vulnerability.
What impact does CVE-2025-42944 have on SAP NetWeaver?
CVE-2025-42944 allows unauthenticated attackers to execute arbitrary commands on the operating system through the RMI-P4 module.
What are the signs of exploitation of CVE-2025-42944?
Signs of exploitation may include unexpected behaviors, increased network traffic to open ports, or unusual system performance.
Is CVE-2025-42944 associated with a specific version of SAP NetWeaver?
CVE-2025-42944 affects SAP NetWeaver and requires vigilance across all installations utilizing the vulnerable RMI-P4 module.