External risk intelligence

SAP jConnect Deserialization RCE

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-42928

The vulnerability exists in SAP jConnect and requires a high-privileged user to exploit. While it involves network-based deserialization, the requirement for high-privileged access typically restricts the attack surface to authenticated internal administrative contexts rather than public-facing services.

Deserialization

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in SAP jConnect, which could allow a highly privileged user to execute remote code. Exploitation can impact system confidentiality, integrity, and availability. The main concern at this time is confirming relevance and exposure to our environment.

  • A flaw allows privileged users to run unauthorized code.
  • High privileges are needed for a potential attack.
  • Confirm if this SAP component is in use.

Attack Path

How an attacker could exploit the issue

An attacker with high privileges on a system using SAP jConnect could exploit a deserialization flaw by sending specially crafted input. This vulnerability, present in the SAP jConnect component, could allow an attacker to execute arbitrary code remotely, leading to a significant compromise of the system's confidentiality, integrity, and availability.

  • Requires authenticated, high-privileged user.
  • Triggered by specially crafted input.
  • Leads to remote code execution.

Live Threat

Current exploitation, exposure, and threat context

A deserialization vulnerability in SAP jConnect, when exploited by a high-privileged user with specially crafted input, could lead to remote code execution. This may impact the confidentiality, integrity, and availability of the system.

  • System code and configuration.
  • Unauthenticated remote code execution.
  • Complete system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

SAP system owners and their associated infrastructure or platform teams are likely responsible for addressing this deserialization vulnerability, given its presence in SAP jConnect. The immediate practical first step involves identifying all instances of SAP jConnect, determining their network reachability and business criticality, and then locating the accountable system owner to plan a risk-based remediation.

  • Confirm SAP jConnect inventory and criticality.
  • Identify accountable SAP system owners.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is SAP jConnect?

SAP jConnect is a JDBC driver that acts as a bridge between Java applications and databases, specifically enabling connectivity with SAP SQL Anywhere and Sybase databases. It is a foundational component often embedded within enterprise software to handle data communication and persistence layers.

How does this deserialization vulnerability work in CVE-2025-42928?

This flaw belongs to the CWE-502 weakness class, where an application trusts and processes malicious, serialized object data from an untrusted source. When the software reconstructs this specially crafted input, it can unintentionally execute unauthorized, arbitrary commands, leading to full system compromise.

Does any input trigger this flaw?

No; the vulnerability is not triggered by just any input. It specifically requires a user who already possesses high-level system privileges to submit the malicious, crafted data. The system remains stable when processing standard, expected data types.

Is my system at risk if it isn't internet-facing?

Halo Surface Signal indicates the risk is unlikely for public-facing services because exploitation requires pre-existing high-privileged access. The primary concern is typically limited to authenticated internal administrative environments where someone already has significant control.

What should I do first if I run SAP jConnect?

Begin by auditing your software inventory to locate every instance of SAP jConnect within your infrastructure. Once identified, determine the business criticality of those specific systems and connect with the designated system owners to assess your exposure and coordinate necessary security updates.

References