SAP NetWeaver Enterprise Portal Administration Deserialization Vulnerability Leading to High Impact on System Confidentiality, Integrity, and Availability
Vulnerability
A vulnerability exists in SAP NetWeaver Enterprise Portal Administration that allows a privileged user to upload untrusted or malicious content. This content, upon deserialization, could significantly compromise the confidentiality, integrity, and availability of the host system.
Impact
Exploitation of this vulnerability could result in a severe impact on the confidentiality, integrity, and availability of the affected system.
Remediation
Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, where a complete list of all security notes is available. Security fixes for SAP NetWeaver based products are also delivered with the support packages.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
