Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-76j3-vxfx-99xf

Опубликовано: 08 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting attackers complete control over the affected system. This results in a severe impact on the confidentiality, integrity, and availability of the application and host environment.

A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting attackers complete control over the affected system. This results in a severe impact on the confidentiality, integrity, and availability of the application and host environment.

EPSS

Процентиль: 52%
0.0074
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.1
nvd
около 1 года назад

A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting attackers complete control over the affected system. This results in a severe impact on the confidentiality, integrity, and availability of the application and host environment.

CVSS3: 9.1
fstec
около 1 года назад

Уязвимость сервера приложений SAP NetWeaver Application Server Java, связанная с недостатками механизма десериализации, позволяющая нарушителю полностью компрометировать систему

EPSS

Процентиль: 52%
0.0074
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-502