Authenticated Unsecure Java Deserialization in SAP NetWeaver JAVA Enterprise Portal Federated Portal Network
July 30, 2026
Authenticated Unsecure Java Deserialization in SAP NetWeaver JAVA Enterprise Portal Federated Portal Network
Impact on Business
A remote, authenticated attacker with high privileges can exploit a Java deserialization vulnerability to execute arbitrary operating system commands. This can lead to a full compromise of the affected system, severely impacting the confidentiality, integrity, and availability of the business applications and underlying infrastructure.
Vulnerability Details
A Java deserialization vulnerability exists in the SAP Enterprise Portal Federated Portal Network. The application insecurely deserializes untrusted data sent via specific HTTP requests after authentication verification. An authenticated attacker with administrative privileges can craft a malicious serialized object, which upon deserialization, allows for the execution of arbitrary operating system commands as the highly privileged system user (sidadm). This bypasses standard application controls and leaves minimal traces, posing a critical risk to the system.
Solution
SAP has released SAP Note 3620498 which provides patched versions of the affected components.
The patches can be downloaded from https://me.sap.com/notes/3620498.
Onapsis strongly recommends SAP customers to download the related security fixes and apply them to the affected components in order to reduce business risks.
Report Timeline
- 05/14/2025: Onapsis reports vulnerability to SAP
- 07/08/2025: SAP issues the patch
References
Advisory Information
- Public Release Date: 07/30/2026
- Security Advisory ID: ONAPSIS-2026-0013
- Researcher(s): Fabian Hagg, Pablo Artuso, Yvan Genuer
Vulnerability Information
- Vendor: SAP
- Affected Components: SAP NetWeaver JAVA (Enterprise Portal Federated Portal Network) (Check SAP Note 3620498 for detailed information on affected releases)
- Vulnerability Class: CWE-502: Deserialization of Untrusted Data
- CVSS v3 score: 9.1 (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- Risk Level: Critical
- Assigned CVE: CVE-2025-42980
- Vendor patch Information: SAP Security NOTE 3620498
Affected Components Description
The vulnerability affects the SAP NetWeaver JAVA platform, specifically within the Enterprise Portal Federated Portal Network component. Testing was confirmed on SAP NetWeaver JAVA 7.50.

About our Research Labs
Onapsis Research Labs provides the industry analysis of key security issues that impact mission-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Research Labs combine in-depth knowledge and experience to deliver technical and business-context with sound security judgment to the broader information security community.
Find all reported vulnerabilities at: https://github.com/Onapsis/vulnerability_advisories
This advisory is licensed under a Creative Commons 4.0 BY-ND International License
