CVE 4.4 MEDIUM

Insecure Deserialization vulnerability in SAP NetWeaver (JMS service)_CVE-2026-23685

4.4 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Description

Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger unintended behavior during internal logic execution, potentially causing a denial of service. Successful exploitation results in a high impact on availability, while confidentiality and integrity remain unaffected.

Basic Information

ID CVE-2026-23685
Source sap
Published Feb 10, 2026 at 03:02

Affected Product

Vendor SAP_SE
Product SAP NetWeaver (JMS service)
Version J2EE-FRMW 7.50
Affected Versions SAP_SE SAP NetWeaver (JMS service) J2EE-FRMW 7.50

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.