14.3 C
New York
Tuesday, October 14, 2025

SAP Patches Vital NetWeaver (CVSS As much as 10.0) and Excessive-Severity S/4HANA Flaws


Sep 10, 2025Ravie LakshmananSoftware program Safety / Vulnerability

SAP Patches Vital NetWeaver (CVSS As much as 10.0) and Excessive-Severity S/4HANA Flaws

SAP on Tuesday launched safety updates to deal with a number of safety flaws, together with three important vulnerabilities in SAP Netweaver that might end in code execution and the add arbitrary information.

The vulnerabilities are listed beneath –

  • CVE-2025-42944 (CVSS rating: 10.0) – A deserialization vulnerability in SAP NetWeaver that might permit an unauthenticated attacker to submit a malicious payload to an open port via the RMI-P4 module, leading to working system command execution
  • CVE-2025-42922 (CVSS rating: 9.9) – An insecure file operations vulnerability in SAP NetWeaver AS Java that might permit an attacker authenticated as a non-administrative person to add an arbitrary file
  • CVE-2025-42958 (CVSS rating: 9.1) – A lacking authentication verify vulnerability within the SAP NetWeaver software on IBM i-series that might permit extremely privileged unauthorized customers to learn, modify, or delete delicate data, in addition to entry administrative or privileged functionalities
Audit and Beyond

“[CVE-2025-42944] permits an unauthenticated attacker to execute arbitrary OS instructions by submitting a malicious payload to an open port,” Onapsis stated. “A profitable exploit can result in full compromise of the appliance. As a brief workaround, clients ought to add P4 port filtering on the ICM stage to forestall unknown hosts from connecting to the P4 port.”

Additionally addressed by SAP is a high-severity lacking enter validation bug in SAP S/4HANA (CVE-2025-42916, CVSS rating: 8.1) that might allow an attacker with excessive privilege entry to ABAP studies to delete the content material of arbitrary database tables, ought to the tables not be protected by an authorization group.

The patches arrive days after SecurityBridge and Pathlock disclosed {that a} important safety defect in SAP S/4HANA that was mounted by the corporate final month (CVE-2025-42957, CVSS rating: 9.9) has come beneath energetic exploitation within the wild.

Whereas there isn’t any proof that the newly disclosed points have been weaponized by unhealthy actors, it is important that customers transfer to use the required updates as quickly as doable for optimum safety.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles