3634501 - [CVE-2025-42944] Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)

news/2025/9/20 8:20:05/文章来源:https://www.cnblogs.com/weikui/p/19101983

3634501 - [CVE-2025-42944] Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)

Symptom

Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high impact to the application's confidentiality, integrity, and availability.

Change Log:

v38 (Current Version)  - UPDATE 12th September 2025: This note has been re-released with updated instructions in the 'Workaround' section.

v34 (Previous Version) - UPDATE 10th September 2025: This note has been re-released with updated instructions in the 'Workaround' section.

v33 (Initial Version released to customers)

Other Terms

OS command execution, Remote Code Execution, Insecure Deserialization, CVE-2025-42944

Reason and Prerequisites

Insecure Deserialization of untrusted or malicious content

Solution

The issue was resolved by updating the affected P4-Lib component to enforce secure deserialization handling and restrict the acceptance of untrusted Java objects via the RMI-P4 module.

Please implement the patches listed in the "Support Packages & Patches" section of this SAP Security Note. Note that the prerequisite to apply this patch is that a Java virtual Machine with java version greater than Java 8 u121 (April 18, 2017) must be in place. Please update JVM if needed: Note 2695197

To avoid incompatibilities on the system, please check SAP Note 1974464 (Information on SCA Dependency Analysis for Java download objects) before applying the update.

  • For additional information or questions regarding the patch, see 3637718.

 

Workaround

If your system is already isolated on network level and P4 and P4S ports are not accessible by insecure networks, then the workaround is already in place and you can skip the below information.

Please assess the workaround applicability for your SAP landscape prior to implementation.
This only affects AS Java (where ICM is used), not Web Dispatcher(WD) as web dispatcher itself doesn't support P4/P4S protocol - it doesn't open P4/P4S ports.

Note that this workaround has to be applied only when/while a patch/SP Update is not possible. SAP strongly recommends you apply the corrections outlined in the security note, which can be done in lieu of the workaround or after the workaround is implemented. The workaround can be rolled-back after patch/SP update is applied if needed.

The workaround involves ensuring that your system is properly isolated at the network level, with the P4/P4S ports only listening on IP addresses from your internal network. If P4/P4S is exposed with public access, you need to be cautious and apply additional security measures.

If you need client IP filtering, https://help.sap.com/docs/ABAP_PLATFORM_NEW/683d6a1797a34730a6e005d1e8de6f22/0c39b84c3afe4d2d9f9f887a32914ecd.html?locale=en-US - this is applicable only for P4 and P4S.

Steps to execute:

1. Ensure only trusted systems are reachable on this interface through network-level controls (e.g., firewall rules).

2. Plan and schedule a patch or SP update as soon as possible to eliminate the underlying vulnerability.


The workaround involves any network configurations that can limit the visibility of P4/P4S port. You can test with telnet <ASJ_host> <p4_port i.e. 50004> from an outside network to see if it is reachable. You can check SAP MMC -> Access Points to see on which IPs P4/P4S port is listening. Involve your network/OS administrator to check and configure the setup.
Note: Implementing the workaround should be considered carefully when there are P4 clients such as SUM, Solution Manager, IB, and others.

本文来自互联网用户投稿,该文观点仅代表作者本人,不代表本站立场。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如若转载,请注明出处:http://www.mzph.cn/news/908211.shtml

如若内容造成侵权/违法违规/事实不符,请联系多彩编程网进行投诉反馈email:809451989@qq.com,一经查实,立即删除!

相关文章

【无人艇协同】基于matlab面向海事安全的双体无人艇分布式协同任务规划(目标函数:总时间满意度)【含Matlab源码 14161期】博士论文 - 教程

pre { white-space: pre !important; word-wrap: normal !important; overflow-x: auto !important; display: block !important; font-family: "Consolas", "Monaco", "Courier New", …

实用指南:Unity 打包 iOS,Xcode 构建并上传 App Store

pre { white-space: pre !important; word-wrap: normal !important; overflow-x: auto !important; display: block !important; font-family: "Consolas", "Monaco", "Courier New", …

实用指南:GitHub 热榜项目 - 日榜(2025-09-09)

pre { white-space: pre !important; word-wrap: normal !important; overflow-x: auto !important; display: block !important; font-family: "Consolas", "Monaco", "Courier New", …

深入解析:【Fiora深度解析】手把手教你用固定公网IP搭建专属聊天系统!

深入解析:【Fiora深度解析】手把手教你用固定公网IP搭建专属聊天系统!2025-09-20 08:13 tlnshuju 阅读(0) 评论(0) 收藏 举报pre { white-space: pre !important; word-wrap: normal !important; overflow-x: au…

使用JavaScript和CSS创建动态高亮导航栏

本文详细介绍了两种实现动态高亮导航栏的技术方案:第一种使用getBoundingClientRect方法精确计算元素位置和尺寸,第二种利用新兴的View Transition API简化动画实现。文章包含完整的代码示例和实际演示,适合前端开发…

wxt 开发浏览器插件的框架

wxt 开发浏览器插件的框架wxt 开发浏览器插件的框架 支持的特性支持所有浏览器 支持mv2 以及mv3 协议 开发模式支持热更新 基于文件的entrypoints 基于ts 开发 支持自动导入 自动发布 支持vue,react,svelte 等框架说…

Gridspech 全通关

You made it to the end of Gridspech. Thank you for playing!!A1A2A3A4A5A6A7A8A9A10A11A12A13A14

20253320蒋丰任

1.我叫蒋丰任,是一个阳光开朗大男孩,因为有一首我挺喜欢的歌就叫这个,同时我的朋友和我自己都认为我是一个外向的社牛(在广东,到了北京,比起东北大哥的热情,我自愧不如)。 2.办公软件的使用(Excel),一定要谦…

又有两位智驾大牛联手入局具身智能机器人赛道创业,已完成数亿元融资!

微信视频号:sph0RgSyDYV47z6快手号:4874645212抖音号:dy0so323fq2w小红书号:95619019828B站1:UID:3546863642871878B站2:UID: 3546955410049087最新资讯,[元璟资本]投资合伙人、原[理想汽车]CTO王凯已入局具身智…

纯国产GPU性能对比,谁才是国产算力之王?

微信视频号:sph0RgSyDYV47z6快手号:4874645212抖音号:dy0so323fq2w小红书号:95619019828B站1:UID:3546863642871878B站2:UID: 3546955410049087 显存规格:存储能力大比拼在显存规格这一块,百度昆仑芯 3 代 P8…

地平线明年发布并争取量产舱驾一体芯片;比亚迪补强智舱团队,斑马智行原 CTO 加入

微信视频号:sph0RgSyDYV47z6快手号:4874645212抖音号:dy0so323fq2w小红书号:95619019828B站1:UID:3546863642871878B站2:UID: 3546955410049087 地平线舱驾一体芯片 2026 年发布与量产汽车智能芯片的竞赛还在继续…

英伟达入股英特尔,当竞争对手便成协作者,真正受益的......

微信视频号:sph0RgSyDYV47z6快手号:4874645212抖音号:dy0so323fq2w小红书号:95619019828B站1:UID:3546863642871878B站2:UID: 3546955410049087就在今天(9月18日),全球半导体行业迎来历史性时刻——英伟达宣布…

ODT/珂朵莉树 入门

主打一个看到别人学什么我学什么,反正什么也不会。 什么是 ODT 是一种数据结构 类比线段树的话,他的每一条线段(一个基本单位)记录了相同 "颜色" 的东西的信息 使用一个结构体的 \(set\),记录 区间 \([…

博客更新公告

来看看博客更新公告吧rt. 公示最新更新或发布的博客, 供大家查阅. 更新日志 Upd 2025.9.18 新随笔 Skywalk -- Words to be remembered 2025.9.18 网址: https://www.cnblogs.com/hsy8116/p/19099273.Upd 2025.9.12 新…

在AI技术快速实现功能的时代,挖掘新需求成为关键突破点——某知名游戏资源分析工具需求洞察

本文基于某知名游戏资源分析工具的文档和用户反馈,深入分析其核心功能和应用场景,并识别出用户提出的潜在新需求,包括纹理自动映射、改进构建方法和增强类型过滤等功能优化方向。a.内容描述核心功能定位:该项目是一…

【光照】[漫反射]UnityURP兰伯特有光照衰减吗?

【从UnityURP开始探索游戏渲染】专栏-直达光照衰减的基本原理 在物理正确的光照模型中,衰减需要遵循两个基本定律:‌平方反比定律‌:光强与距离平方成反比 (I ∝ 1/r) ‌余弦定律‌:表面接收的光强与入射角余弦成正…

手把手带你从零开始实现一个编译器

手把手带你从零开始实现一个编译器https://www.cnblogs.com/abinzhao/p/18748462其实我之前写过关于编译器方面的文章,昨天写了一篇关于通过自制适合自己的JavaScript语法的文章,但是被某个掘友说不懂编译,误人子弟…

prenotami.esteri.it 意大利签证预约error

可以尝试重新登录一下账号,可能会好

绯闻女孩不只会八卦:从“验明正身”到“抓内鬼”,Gossip的进阶玩法

绯闻女孩不只会八卦:从“验明正身”到“抓内鬼”,Gossip的进阶玩法默克尔树 默克尔树(Merkle Tree)是由计算机科学家Ralph Merkle多年前提出,并以他本人的名字来命名,也叫哈希树。默克尔树是一种树形数据结构,通…