Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SAP Patches Critical S/4HANA Vulnerability

SAP Patches Critical S/4HANA Vulnerability

Posted on August 12, 2025August 12, 2025 By CWS

SAP has mounted greater than a dozen vulnerabilities with its August 2025 Patch Tuesday updates, together with essential vulnerabilities. 

This Patch Tuesday — or because the enterprise software program large calls it, Safety Patch Day — 15 new safety notes (fixes) have been launched, together with 4 updates to earlier fixes.

Onapsis, an organization specializing in enterprise software safety, which frequently finds SAP product vulnerabilities, identified that the seller has launched a complete of 26 new and up to date fixes for the reason that earlier Patch Tuesday.

Of those 26 fixes, 4 have been categorised as ‘sizzling information’ or ‘essential’, together with two which can be new and two updates to earlier patches. The brand new ‘sizzling information’ patches are for CVE-2025-42950 and CVE-2025-42957, which have been described as code injection points.

Based on Onapsis, they are often exploited for arbitrary code execution, which might result in a full system compromise. 

CVE-2025-42950 and CVE-2025-42957 are the identical vulnerability, Onapsis mentioned, however totally different CVEs have been assigned to totally different merchandise. CVE-2025-42957 has been assigned to the S/4HANA enterprise useful resource planning (ERP) software program, whereas CVE-2025-42950 is for the older era of the ERP software program, ERP Central Part (ECC). 

The brand new high-priority patches deal with a damaged authorization problem in SAP Enterprise One (CVE-2025-42951, permits an authenticated attacker to acquire admin privileges), and a number of reminiscence corruption bugs in NetWeaver Utility Server ABAP (CVE-2025-42976, can result in delicate info leaks).

The remaining new points, which have ‘low’ or ‘medium’ precedence, influence S/4HANA, NetWeaver, ABAP Platform, Cloud Connector and different merchandise.Commercial. Scroll to proceed studying.

It’s vital for organizations to put in the obtainable updates because it’s not unusual for risk actors to take advantage of SAP product vulnerabilities of their assaults. 

SAP clients had been not too long ago warned {that a} NetWeaver zero-day flaw patched in April had been exploited since at the least January. NetWeaver vulnerabilities have been exploited not too long ago by each ransomware teams and cyberspies. 

Associated: SAP Patches Important Flaws That Might Enable Distant Code Execution, Full System Takeover

Associated: Important Vulnerability Patched in SAP NetWeaver

Associated: SAP Patches One other Exploited NetWeaver Vulnerability

Security Week News Tags:Critical, Patches, S4HANA, SAP, Vulnerability

Post navigation

Previous Post: Enterprise Browsers vs. Secure Browser Extensions
Next Post: North Korean Kimsuky Hackers Data Breach

Related Posts

RapidFort Secures M to Enhance Software Security Automation RapidFort Secures $42M to Enhance Software Security Automation Security Week News
Microsoft Addresses 83 Security Vulnerabilities in March Update Microsoft Addresses 83 Security Vulnerabilities in March Update Security Week News
Large Interpol Cybercrime Crackdown in Africa Leads to the Arrest of Over 1,200 Suspects Large Interpol Cybercrime Crackdown in Africa Leads to the Arrest of Over 1,200 Suspects Security Week News
Securonix Acquires Threat Intelligence Firm ThreatQuotient Securonix Acquires Threat Intelligence Firm ThreatQuotient Security Week News
New HTTP Request Smuggling Attacks Impacted CDNs, Major Orgs, Millions of Websites New HTTP Request Smuggling Attacks Impacted CDNs, Major Orgs, Millions of Websites Security Week News
Anthropic Pauses AI Models Amid U.S. Export Controls Anthropic Pauses AI Models Amid U.S. Export Controls Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Highlights Critical Security Flaws in Artifactory and RouterOS
  • VLC Media Player Security Flaws Pose Serious Risks
  • Enhancing Security: Tackling Cloud Supply-Chain Threats
  • AI-Driven Cyber Threats Demand Swift Security Upgrades
  • BlueMoon Exploit Kit Targets Chrome and Windows Zero-Days

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Highlights Critical Security Flaws in Artifactory and RouterOS
  • VLC Media Player Security Flaws Pose Serious Risks
  • Enhancing Security: Tackling Cloud Supply-Chain Threats
  • AI-Driven Cyber Threats Demand Swift Security Upgrades
  • BlueMoon Exploit Kit Targets Chrome and Windows Zero-Days

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark