CVE-2025-42964: Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration
SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42964?
CVE-2025-42964 is considered a high-severity vulnerability due to its potential impact on confidentiality, integrity, and availability.
How do I fix CVE-2025-42964?
To fix CVE-2025-42964, ensure that your SAP NetWeaver Enterprise Portal Administration is updated to the latest patch provided by SAP.
Who is affected by CVE-2025-42964?
CVE-2025-42964 affects systems running SAP NetWeaver Enterprise Portal Administration that allow privileged users to upload content.
What type of attack does CVE-2025-42964 enable?
CVE-2025-42964 enables attacks that involve the deserialization of untrusted content, potentially compromising the host system.
Is there a workaround for CVE-2025-42964?
Currently, the recommended method to mitigate CVE-2025-42964 is to apply the security patches released by SAP as there is no published workaround.