logo

SAP fixes three critical vulnerabilities across multiple products

ID: 905eb0ed-9aac-5087-8f49-70fac43b6716

STIX ID: report--905eb0ed-9aac-5087-8f49-70fac43b6716

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-12-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

SAP published its December 2025 security bulletin fixing 14 vulnerabilities across products, including three critical issues: a code-injection flaw in SAP Solution Manager (CVSS 9.9), Apache Tomcat-related vulnerabilities affecting SAP Commerce Cloud (CVSS 9.6), and a deserialization issue in SAP jConnect (CVSS 9.1). The bulletin includes additional high- and medium-severity fixes; SAP has not flagged these 14 as actively exploited, but given SAP's widespread enterprise usage and prior in-the-wild abuse of other SAP vulnerabilities, administrators are advised to patch without delay.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.