CVE-2025-42980 is a critical deserialization vulnerability in SAP NetWeaver Enterprise Portal Federated Portal Network. A highly privileged attacker can upload malicious content, leading to a complete compromise of the host system's confidentiality, integrity, and availability. With a CVSS score of 9.1 (CRITICAL), this vulnerability is easily exploitable over the network with no user interaction required. While there is no public exploit code or active exploitation reported, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SAP SE | SAP NetWeaver Enterprise Portal Federated Portal Network | EP-RUNTIME 7.50CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.