CVE-2025-42966

SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization vulnerability by sending a specially crafted serialized Java object. This could lead to high impact on confidentiality, integrity, and availability of the application.
Configurations

No configuration.

History

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) SAP NetWeaver XML Data Archiving Service permite a un atacante autenticado con privilegios administrativos explotar una vulnerabilidad de deserialización de Java insegura mediante el envío de un objeto Java serializado especialmente manipulado. Esto podría afectar gravemente la confidencialidad, la integridad y la disponibilidad de la aplicación.

08 Jul 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-08 01:15

Updated : 2025-07-08 16:18


NVD link : CVE-2025-42966

Mitre link : CVE-2025-42966

CVE.ORG link : CVE-2025-42966


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data