CVE-2025-42874

7.9

SAP · NetWeaver (remote service for Xcelsius)

SAP NetWeaver remote service for Xcelsius is vulnerable to remote code execution due to improper input validation, requiring high-level administrative privileges for exploitation.

Executive summary

An improper input validation vulnerability in SAP NetWeaver allows highly privileged, network-authenticated attackers to execute arbitrary code and compromise system integrity.

Vulnerability

The vulnerability stems from insufficient input validation and improper handling of remote method calls within the Xcelsius remote service. An attacker must possess high privileges to successfully trigger this issue, which leads to arbitrary code execution.

Business impact

Successful exploitation of this vulnerability poses a severe risk to the integrity and availability of SAP environments. With a CVSS score of 7.9, this high-severity flaw could allow an attacker to gain unauthorized system control, potentially resulting in significant operational disruption or the modification of sensitive business data.

Remediation

Immediate Action: Review the official SAP Security Note 3640185 and apply the provided security patches or configuration changes to the affected NetWeaver components as soon as possible.

Proactive Monitoring: Monitor system and application logs for unusual remote method call patterns or unexpected process execution originating from the Xcelsius service account.

Compensating Controls: Restrict network access to the affected service to authorized management interfaces only, and ensure that strict privilege management policies are enforced for all administrative accounts.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

Given the potential for total impact on system integrity and availability, administrators should prioritize the assessment of their SAP NetWeaver landscape. Apply the necessary vendor-supplied updates immediately upon release to neutralize the risk of arbitrary code execution.

More SAP CVEs

Sources