Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

SAP Patches Critical Vulnerabilities in NetWeaver, Print Service, SRM

Posted on October 14, 2025October 14, 2025 By CWS

Enterprise software program maker SAP on Tuesday introduced the discharge of 16 new and up to date patch notes as a part of its month-to-month rollout, together with three contemporary notes that deal with critical-severity vulnerabilities.

One of many patches launched on October 2025 Safety Patch Day resolves as soon as once more CVE-2025-42944 (CVSS rating of 10/10), described as an insecure deserialization flaw in NetWeaver AS Java.

Based on enterprise software program safety agency Onapsis, the safety notice provides contemporary protections to insecure deserialization flaws resolved in NetWeaver over the previous months, together with CVE-2025-42944, which was initially patched in September 2025.

The truth is, SAP additionally up to date the September 2025 safety notice coping with CVE-2025-42944, so as to add a reference to the newly launched hardening suggestions.

“The extra layer of safety is predicated on implementing a JVM-wide filter (jdk.serialFilter) that stops devoted lessons from being deserialized,” says Onapsis.

One other critical-severity subject resolved on Tuesday is CVE-2025-42937 (CVSS rating of 9.8), a listing traversal bug in Print Service, which may enable unauthenticated attackers to overwrite system information.

SAP additionally rolled out patches for CVE-2025-42910 (CVSS rating of 9.0), an unrestricted file add defect in Provider Relationship Administration (SRM) that would enable authenticated attackers to add arbitrary information, together with executables containing malware.

This month, SAP printed two safety notes addressing high-severity vulnerabilities. The primary resolves CVE-2025-5115, a denial-of-service (DoS) bug in Commerce Cloud, whereas the second fixes CVE-2025-48913, a safety misconfiguration flaw in Information Hub Integration Suite.Commercial. Scroll to proceed studying.

The remaining 10 new and up to date safety notes resolve medium- and low-severity defects in NetWeaver, ABAP, Commerce Cloud, S/4HANA, Monetary Service Claims Administration, BusinessObjects, and Cloud Equipment.

After the scheduled month-to-month patch day, SAP up to date its September 2025 advisory with one new and 7 up to date safety notes, together with three coping with critical-severity vulnerabilities.

SAP makes no point out of any of those points being exploited within the wild, however customers are suggested to use the patches and mitigations as quickly as doable. Menace actors are identified to have focused SAP bugs of their assaults.

Associated: New Exploit Poses Menace to SAP NetWeaver Situations

Associated: Crucial Vulnerability Patched in SAP NetWeaver

Associated: Oracle Patches EBS Vulnerability Permitting Entry to Delicate Information

Associated: Juniper Networks Patches Crucial Junos Area Vulnerabilities

Security Week News Tags:Critical, NetWeaver, Patches, Print, SAP, Service, SRM, Vulnerabilities

Post navigation

Previous Post: Fraud Prevention Firm Resistant AI Raises $25 Million
Next Post: Sweet Security Named Cloud Security Leader and CADR Leader in Latio Cloud Security Report

Related Posts

Pennsylvania Attorney General Confirms Ransomware Behind Weeks-Long Outage Security Week News
Endpoint Security Firm Remedio Raises $65 Million in First Funding Round Security Week News
OneDrive Gives Web Apps Full Read Access to All Files Security Week News
GPT-5 Has a Vulnerability: Its Router Can Send You to Older, Less Safe Models Security Week News
FreeType Zero-Day Found by Meta Exploited in Paragon Spyware Attacks Security Week News
No Patches for Vulnerabilities Allowing Cognex Industrial Camera Hacking Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft October 2025 Patch Tuesday – 4 Zero-days and 172 Vulnerabilities Patched
  • Chinese Hackers Exploit ArcGIS Server as Backdoor for Over a Year
  • HyperBunker Raises Seed Funding to Launch Next-Generation Anti-Ransomware Device
  • Criminal IP to Showcase ASM and CTI Innovations at GovWare 2025 in Singapore
  • Cybereason Acquired by MSSP Giant LevelBlue

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft October 2025 Patch Tuesday – 4 Zero-days and 172 Vulnerabilities Patched
  • Chinese Hackers Exploit ArcGIS Server as Backdoor for Over a Year
  • HyperBunker Raises Seed Funding to Launch Next-Generation Anti-Ransomware Device
  • Criminal IP to Showcase ASM and CTI Innovations at GovWare 2025 in Singapore
  • Cybereason Acquired by MSSP Giant LevelBlue

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News