SAP NetWeaver Enterprise Portal Administration Deserialization Vulnerability Leading to High Impact on System Confidentiality, Integrity, and Availability

Vulnerability

A vulnerability exists in SAP NetWeaver Enterprise Portal Administration that allows a privileged user to upload untrusted or malicious content. This content, upon deserialization, could significantly compromise the confidentiality, integrity, and availability of the host system.

Impact

Exploitation of this vulnerability could result in a severe impact on the confidentiality, integrity, and availability of the affected system.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, where a complete list of all security notes is available. Security fixes for SAP NetWeaver based products are also delivered with the support packages.

Added: Mar 10, 2026, 6:13 PM
Updated: Mar 10, 2026, 6:13 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
3.8
remediation
0.0
relevance
3.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.