Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-76j3-vxfx-99xf

Опубликовано: 08 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting attackers complete control over the affected system. This results in a severe impact on the confidentiality, integrity, and availability of the application and host environment.

A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting attackers complete control over the affected system. This results in a severe impact on the confidentiality, integrity, and availability of the application and host environment.

EPSS

Процентиль: 36%
0.00149
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.1
nvd
7 месяцев назад

A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting attackers complete control over the affected system. This results in a severe impact on the confidentiality, integrity, and availability of the application and host environment.

CVSS3: 9.1
fstec
7 месяцев назад

Уязвимость сервера приложений SAP NetWeaver Application Server Java, связанная с недостатками механизма десериализации, позволяющая нарушителю полностью компрометировать систему

EPSS

Процентиль: 36%
0.00149
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-502