SAP fixes three critical vulnerabilities across multiple products
ID: 905eb0ed-9aac-5087-8f49-70fac43b6716
STIX ID: report--905eb0ed-9aac-5087-8f49-70fac43b6716
Feed Name: Bleeping Computer
SAP published its December 2025 security bulletin fixing 14 vulnerabilities across products, including three critical issues: a code-injection flaw in SAP Solution Manager (CVSS 9.9), Apache Tomcat-related vulnerabilities affecting SAP Commerce Cloud (CVSS 9.6), and a deserialization issue in SAP jConnect (CVSS 9.1). The bulletin includes additional high- and medium-severity fixes; SAP has not flagged these 14 as actively exploited, but given SAP's widespread enterprise usage and prior in-the-wild abuse of other SAP vulnerabilities, administrators are advised to patch without delay.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
