Authenticated Unsecure Java Deserialization in SAP NetWeaver JAVA Enterprise Portal Federated Portal Network

July 30, 2026

Authenticated Unsecure Java Deserialization in SAP NetWeaver JAVA Enterprise Portal Federated Portal Network


Impact on Business

A remote, authenticated attacker with high privileges can exploit a Java deserialization vulnerability to execute arbitrary operating system commands. This can lead to a full compromise of the affected system, severely impacting the confidentiality, integrity, and availability of the business applications and underlying infrastructure.


Vulnerability Details

A Java deserialization vulnerability exists in the SAP Enterprise Portal Federated Portal Network. The application insecurely deserializes untrusted data sent via specific HTTP requests after authentication verification. An authenticated attacker with administrative privileges can craft a malicious serialized object, which upon deserialization, allows for the execution of arbitrary operating system commands as the highly privileged system user (sidadm). This bypasses standard application controls and leaves minimal traces, posing a critical risk to the system.


Solution

SAP has released SAP Note 3620498 which provides patched versions of the affected components.

The patches can be downloaded from https://me.sap.com/notes/3620498.

Onapsis strongly recommends SAP customers to download the related security fixes and apply them to the affected components in order to reduce business risks.


Report Timeline

  • 05/14/2025: Onapsis reports vulnerability to SAP
  • 07/08/2025: SAP issues the patch

References


Advisory Information

  • Public Release Date: 07/30/2026
  • Security Advisory ID: ONAPSIS-2026-0013
  • Researcher(s): Fabian Hagg, Pablo Artuso, Yvan Genuer

Vulnerability Information

  • Vendor: SAP
  • Affected Components: SAP NetWeaver JAVA (Enterprise Portal Federated Portal Network) (Check SAP Note 3620498 for detailed information on affected releases)
  • Vulnerability Class: CWE-502: Deserialization of Untrusted Data
  • CVSS v3 score: 9.1 (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
  • Risk Level: Critical
  • Assigned CVE: CVE-2025-42980
  • Vendor patch Information: SAP Security NOTE 3620498

Affected Components Description

The vulnerability affects the SAP NetWeaver JAVA platform, specifically within the Enterprise Portal Federated Portal Network component. Testing was confirmed on SAP NetWeaver JAVA 7.50.

About our Research Labs

Onapsis Research Labs provides the industry analysis of key security issues that impact mission-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Research Labs combine in-depth knowledge and experience to deliver technical and business-context with sound security judgment to the broader information security community.

Find all reported vulnerabilities at: https://github.com/Onapsis/vulnerability_advisories

This advisory is licensed under a Creative Commons 4.0 BY-ND International License