SAP NetWeaver Enterprise Portal Administration Deserialization Vulnerability Allowing Confidentiality, Integrity, and Availability Compromise
Vulnerability
A vulnerability exists in SAP NetWeaver Enterprise Portal Administration that allows a privileged user to upload untrusted or malicious content. This content, when deserialized, could potentially compromise the confidentiality, integrity, and availability of the host system.
Impact
Exploitation of this vulnerability could lead to a deserialization issue, allowing for potential arbitrary code execution or manipulation of the application state, depending on the deserialized content.
Remediation
Users are advised to review and implement the latest SAP Security Notes. Security fixes for SAP NetWeaver based products are delivered with the support packages. For guidance on applying these security notes, refer to the SAP Security Notes FAQ.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
