logo

SAP fixes critical vulnerabilities in NetWeaver application servers

ID: f4ed3a4a-8a85-5fe9-963e-5a3811922998

STIX ID: report--f4ed3a4a-8a85-5fe9-963e-5a3811922998

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-01-15

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

SAP released patches in its January Security Patch Day addressing two critical NetWeaver vulnerabilities (CVEs 2025-0070 and 2025-0066, CVSS 9.9) and several high-severity issues including an SQL injection (CVE-2025-0063) and session hijacking (CVE-2025-0061); these flaws can enable privilege escalation, information disclosure, database compromise, and session takeover, and SAP urges customers to apply updates promptly to protect enterprise environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.