CVE-2026-23685
Insecure Deserialization vulnerability in SAP NetWeaver (JMS service)
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 4.4EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
10 fev 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger unintended behavior during internal logic execution, potentially causing a denial of service. Successful exploitation results in a high impact on availability, while confidentiality and integrity remain unaffected.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Produtos afetados
SAP_SE · SAP NetWeaver (JMS service)Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →