logo

SAP fixes maximum severity NetWeaver command execution flaw

ID: e40c9b38-bd2b-5cf5-a3dd-0fa584ffa612

STIX ID: report--e40c9b38-bd2b-5cf5-a3dd-0fa584ffa612

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-09-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

SAP released a September security bulletin addressing 21 vulnerabilities across its products, highlighting three critical NetWeaver issues including an unauthenticated insecure-deserialization RMI-P4 flaw enabling remote OS command execution (CVE-2025-42944), a file upload flaw allowing potential full compromise (CVE-2025-42922), and a missing-auth check granting high-privilege access to sensitive data (CVE-2025-42958); administrators are advised to apply vendor patches and mitigations, noting that another critical SAP vulnerability (CVE-2025-42957) has been reported exploited in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.