New SAP NetWeaver AS Java CVE-2025-42944: Critical Insecure Deserialization Enables Pre-Auth Takeover via RMI-P4

Introduction: what happened and why it matters SAP has released fixes and additional hardening for a maximum-severity (CVSS 10.0) vulnerability in SAP NetWeaver AS Java: CVE-2025-42944. The flaw is an insecure deserialization issue reachable without authentication through the RMI-P4 interface,…
