CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-42874: SAP NetWeaver (remote service for Xcelsius) BI-BASE-E 7.50, BI-BASE-B 7.50, BI-IBC 7.50, BI-BASE-S 7.50, BIWEBAPP 7.50

CVE-2025-42874. CVSS 3.1 base score 7.9 (HIGH, Vendor/CNA). EPSS 0.00469 (percentile 0.38481), scored 2026-10-06.

Affected technology

SAP NetWeaver (remote service for Xcelsius) · BI-BASE-E 7.50, BI-BASE-B 7.50, BI-IBC 7.50, BI-BASE-S 7.50, BIWEBAPP 7.50
SAP_SE

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · High privileges required · No user interaction required

What an attacker can do

An attacker with network access and high privileges can execute arbitrary code on the affected system due to insufficient input validation and improper handling of remote method calls. Vendor/CNA’s CVSS 3.1 assessment (base score 7.9/10) rates confidentiality impact as low; integrity and availability impact as high.

Published

CWE
CWE-405
CCR priority
31.7 /100 (P4)
CVSS 3.1
7.9 /10 · CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:H · Vendor/CNA
EPSS
0.00469 · percentile 0.38481 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-42874.html