Advisory
A note with CVSS 7.1 for component CEC-SCC-INT-HUB was released by SAP on 14.10.2025. The correction/advisory 3658838 was described with "[CVE-2025-48913]Security Misconfiguration vulnerability in SAP Data Hub Integration Suite" and affects the system type SAP Data Hub.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process.
The vulnerability addressed is remote code execution vulnerability within SAP Data Hub.
Risk specification
SAP Data Hub Integration Suite allows an unauthenticated attacker to access JMS configuration interfaces and specify malicious RMI or LDAP URLs, potentially resulting in remote code execution.Solution
Apache CXF libraries have been upgraded to version 3.6.8 to eliminate the misconfiguration vulnerability.
The advisory is valid for
- CX_DATAHUB_INT_PACK 2205
- 9.1 [CVE-2025-42963] Insecure Deserialization in SAP NetWeaver Application Server for Java (Log Viewer )
- 9.1 [CVE-2025-42964] Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration
- 9.1 [CVE-2025-42980] Insecure Deserialization in SAP NetWeaver Enterprise Portal Federated Portal Network
- 9.1 [CVE-2025-42999] Insecure Deserialization in SAP NetWeaver (Visual Composer development server)
- 6.8 Stack overflow vulnerability on the component images of SAP Integration Suite (EDGE INTEGRATION CELL)
