尧图网站建设 尧图网络
  • 首页
  • 关于我们
  • 服务项目
  • 案例展示
  • 建站流程
  • 资讯中心
  • 联系我们
首页/资讯中心/详情

3634501 - [CVE-2025-42944] Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)

3634501 - [CVE-2025-42944] Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)
📅 发布时间:2026/6/20 19:48:44

3634501 - [CVE-2025-42944] Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)

Symptom

Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high impact to the application's confidentiality, integrity, and availability.

Change Log:

v38 (Current Version)  - UPDATE 12th September 2025: This note has been re-released with updated instructions in the 'Workaround' section.

v34 (Previous Version) - UPDATE 10th September 2025: This note has been re-released with updated instructions in the 'Workaround' section.

v33 (Initial Version released to customers)

Other Terms

OS command execution, Remote Code Execution, Insecure Deserialization, CVE-2025-42944

Reason and Prerequisites

Insecure Deserialization of untrusted or malicious content

Solution

The issue was resolved by updating the affected P4-Lib component to enforce secure deserialization handling and restrict the acceptance of untrusted Java objects via the RMI-P4 module.

Please implement the patches listed in the "Support Packages & Patches" section of this SAP Security Note. Note that the prerequisite to apply this patch is that a Java virtual Machine with java version greater than Java 8 u121 (April 18, 2017) must be in place. Please update JVM if needed: Note 2695197

To avoid incompatibilities on the system, please check SAP Note 1974464 (Information on SCA Dependency Analysis for Java download objects) before applying the update.

  • For additional information or questions regarding the patch, see 3637718.

 

Workaround

If your system is already isolated on network level and P4 and P4S ports are not accessible by insecure networks, then the workaround is already in place and you can skip the below information.

Please assess the workaround applicability for your SAP landscape prior to implementation.
This only affects AS Java (where ICM is used), not Web Dispatcher(WD) as web dispatcher itself doesn't support P4/P4S protocol - it doesn't open P4/P4S ports.

Note that this workaround has to be applied only when/while a patch/SP Update is not possible. SAP strongly recommends you apply the corrections outlined in the security note, which can be done in lieu of the workaround or after the workaround is implemented. The workaround can be rolled-back after patch/SP update is applied if needed.

The workaround involves ensuring that your system is properly isolated at the network level, with the P4/P4S ports only listening on IP addresses from your internal network. If P4/P4S is exposed with public access, you need to be cautious and apply additional security measures.

If you need client IP filtering, https://help.sap.com/docs/ABAP_PLATFORM_NEW/683d6a1797a34730a6e005d1e8de6f22/0c39b84c3afe4d2d9f9f887a32914ecd.html?locale=en-US - this is applicable only for P4 and P4S.

Steps to execute:

1. Ensure only trusted systems are reachable on this interface through network-level controls (e.g., firewall rules).

2. Plan and schedule a patch or SP update as soon as possible to eliminate the underlying vulnerability.


The workaround involves any network configurations that can limit the visibility of P4/P4S port. You can test with telnet <ASJ_host> <p4_port i.e. 50004> from an outside network to see if it is reachable. You can check SAP MMC -> Access Points to see on which IPs P4/P4S port is listening. Involve your network/OS administrator to check and configure the setup.
Note: Implementing the workaround should be considered carefully when there are P4 clients such as SUM, Solution Manager, IB, and others.

作者:老应(weikui)
wechat: ywkonline
专注于SAP运维、升级、迁移
出处:http://www.cnblogs.com/weikui/

相关新闻

  • 实用指南:Unity 打包 iOS,Xcode 构建并上传 App Store
  • 20253320蒋丰任
  • 又有两位智驾大牛联手入局具身智能机器人赛道创业,已完成数亿元融资!

最新新闻

  • GDB基础命令
  • 2026上海翡翠回收避坑指南|看懂行情价,拒绝虚高报价套路 - 奢侈品交易观察员
  • ahk2_lib架构解密:构建企业级AutoHotkey V2原生扩展生态
  • 3分钟免费汉化Axure:告别英文界面,拥抱高效中文设计体验
  • 论文AI写作网址有哪些?精选6款正规平台推荐 - 掌桥科研-AI论文写作
  • 2026武汉三新高级技工学校招生简章,23个热门专业覆盖理工、艺术、医学、教育等六个学科方向 - 资讯速览

日新闻

  • 信任的进化:技术实现详解——如何用JavaScript构建博弈论模拟器
  • Terrakube自定义工作流:如何集成OPA、Infracost等工具扩展IaC能力
  • grunt-concurrent快速入门:5分钟学会并行运行Grunt任务

周新闻

  • 3步解锁iOS设备:applera1n激活锁绕过完全指南
  • 39 2026 人工智能证书终极盘点,普通人选 AI 证书可以从这些方向入手
  • Redis 暴露公网有多危险?从端口检查到补救步骤

月新闻

  • 【总结】入门篇:50句话让你记住架构核心概念
  • WeChatMsg技术方案解析:实现Mac微信数据自主管理的完整解决方案
  • WeChatMsg:革新性微信数据备份方案,打造你的专属数字记忆库

关于尧图

  • 公司简介
  • 团队介绍
  • 企业文化
  • 荣誉资质

服务项目

  • 定制开发
  • 电商建站
  • UI 设计
  • 运维服务

快速链接

  • 案例展示
  • 建站流程
  • 常见问题
  • 资讯中心

联系方式

  • 📍北京市朝阳区互联网产业园 A 座 10 层
  • 📞400-888-8888
  • ✉️contact@rkmt.cn
  • 🕐周一至周日 9:00-21:00

© 2024 北京尧图网络科技有限公司 版权所有 | 京 ICP 备 XXXXXXXX 号