CVE-2025-42944

10.0

SAP · SAP NetWeaver

A deserialization vulnerability in the SAP NetWeaver RMI-P4 module allows unauthenticated remote attackers to execute arbitrary code by sending malicious payloads to an open port.

Executive summary

A critical deserialization vulnerability in SAP NetWeaver allows unauthenticated remote attackers to achieve full system compromise via malicious payloads.

Vulnerability

This is a deserialization of untrusted data (CWE-502) vulnerability. The flaw resides in the RMI-P4 module and is remotely exploitable by an unauthenticated attacker, as defined by the CVSS vector AV:N/AC:L/PR:N.

Business impact

The ability for an unauthenticated attacker to remotely execute code grants them full control over the affected SAP system. With a CVSS score of 10.0, this represents the highest level of severity, potentially leading to total system compromise, data exfiltration, and disruption of critical business infrastructure.

Remediation

Immediate Action: Apply the relevant security updates provided in SAP notes 3670067, 3660659, or 3634501 immediately.

Proactive Monitoring: Monitor network traffic for unusual RMI-P4 requests and audit system logs for signs of unauthorized remote code execution.

Compensating Controls: Restrict access to the RMI-P4 port at the network firewall level to only trusted management subnets until the patch is applied.

Exploitation status

Public Exploit Available: Yes — a public proof-of-concept exists on GitHub.

Analyst recommendation

Given the availability of a public proof-of-concept and the critical CVSS score, this vulnerability poses an immediate and severe threat. Organizations must prioritize applying the relevant SAP patches to all vulnerable NetWeaver instances to prevent potential remote exploitation.

More SAP CVEs