SAP fixes maximum severity NetWeaver command execution flaw
ID: e40c9b38-bd2b-5cf5-a3dd-0fa584ffa612
STIX ID: report--e40c9b38-bd2b-5cf5-a3dd-0fa584ffa612
Feed Name: Bleeping Computer
SAP released a September security bulletin addressing 21 vulnerabilities across its products, highlighting three critical NetWeaver issues including an unauthenticated insecure-deserialization RMI-P4 flaw enabling remote OS command execution (CVE-2025-42944), a file upload flaw allowing potential full compromise (CVE-2025-42922), and a missing-auth check granting high-privilege access to sensitive data (CVE-2025-42958); administrators are advised to apply vendor patches and mitigations, noting that another critical SAP vulnerability (CVE-2025-42957) has been reported exploited in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
