SAP fixes critical vulnerabilities in NetWeaver application servers
ID: f4ed3a4a-8a85-5fe9-963e-5a3811922998
STIX ID: report--f4ed3a4a-8a85-5fe9-963e-5a3811922998
Feed Name: Bleeping Computer
Threat Score
SAP released patches in its January Security Patch Day addressing two critical NetWeaver vulnerabilities (CVEs 2025-0070 and 2025-0066, CVSS 9.9) and several high-severity issues including an SQL injection (CVE-2025-0063) and session hijacking (CVE-2025-0061); these flaws can enable privilege escalation, information disclosure, database compromise, and session takeover, and SAP urges customers to apply updates promptly to protect enterprise environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
