SAP NetWeaver Application Server for Java Log Viewer Unsafe Java Object Deserialization Vulnerability Allowing Full Operating System Compromise

Vulnerability

A critical vulnerability has been identified in the Log Viewer component of SAP NetWeaver Application Server for Java. This vulnerability allows authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation of this vulnerability can lead to a full compromise of the operating system, giving attackers complete control over the affected system. This poses a severe risk to the confidentiality, integrity, and availability of both the application and the host environment.

Impact

Exploitation of this vulnerability can result in a full operating system compromise, allowing attackers complete control over the affected system.

Remediation

Users are advised to review and implement the SAP Security Note associated with this vulnerability. This can be done through the SAP for Me platform, where all security notes are available. For guidance on how to access and apply these security notes, refer to the SAP Security Notes FAQs.

Added: Jul 8, 2025, 1:51 AM
Updated: Jul 8, 2025, 1:51 AM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
10.0
exploitability
4.8
remediation
6.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.