SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrary code on the affected system due to insufficient input validation and improper handling of remote method calls. Exploitation does not require user interaction and could lead to service disruption or unauthorized system control. This has high impact on integrity and availability, with no impact on confidentiality.
History

Tue, 09 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap netweaver
Sap sap Netweaver
Vendors & Products Sap
Sap netweaver
Sap sap Netweaver

Tue, 09 Dec 2025 02:30:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrary code on the affected system due to insufficient input validation and improper handling of remote method calls. Exploitation does not require user interaction and could lead to service disruption or unauthorized system control. This has high impact on integrity and availability, with no impact on confidentiality.
Title Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)
Weaknesses CWE-405
References
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-12-09T02:14:19.893Z

Updated: 2025-12-09T16:39:54.601Z

Reserved: 2025-04-16T13:25:17.023Z

Link: CVE-2025-42874

cve-icon Vulnrichment

Updated: 2025-12-09T16:39:51.683Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-09T16:17:51.497

Modified: 2025-12-09T18:36:53.557

Link: CVE-2025-42874

cve-icon Redhat

No data.