SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrary code on the affected system due to insufficient input validation and improper handling of remote method calls. Exploitation does not require user interaction and could lead to service disruption or unauthorized system control. This has high impact on integrity and availability, with no impact on confidentiality.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap netweaver Sap sap Netweaver |
|
| Vendors & Products |
Sap
Sap netweaver Sap sap Netweaver |
Tue, 09 Dec 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrary code on the affected system due to insufficient input validation and improper handling of remote method calls. Exploitation does not require user interaction and could lead to service disruption or unauthorized system control. This has high impact on integrity and availability, with no impact on confidentiality. | |
| Title | Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius) | |
| Weaknesses | CWE-405 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-12-09T02:14:19.893Z
Updated: 2025-12-09T16:39:54.601Z
Reserved: 2025-04-16T13:25:17.023Z
Link: CVE-2025-42874
Updated: 2025-12-09T16:39:51.683Z
Status : Awaiting Analysis
Published: 2025-12-09T16:17:51.497
Modified: 2025-12-09T18:36:53.557
Link: CVE-2025-42874
No data.