Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SAP Patches Critical Vulnerabilities in NetWeaver, Print Service, SRM

SAP Patches Critical Vulnerabilities in NetWeaver, Print Service, SRM

Posted on October 14, 2025October 14, 2025 By CWS

Enterprise software program maker SAP on Tuesday introduced the discharge of 16 new and up to date patch notes as a part of its month-to-month rollout, together with three contemporary notes that deal with critical-severity vulnerabilities.

One of many patches launched on October 2025 Safety Patch Day resolves as soon as once more CVE-2025-42944 (CVSS rating of 10/10), described as an insecure deserialization flaw in NetWeaver AS Java.

Based on enterprise software program safety agency Onapsis, the safety notice provides contemporary protections to insecure deserialization flaws resolved in NetWeaver over the previous months, together with CVE-2025-42944, which was initially patched in September 2025.

The truth is, SAP additionally up to date the September 2025 safety notice coping with CVE-2025-42944, so as to add a reference to the newly launched hardening suggestions.

“The extra layer of safety is predicated on implementing a JVM-wide filter (jdk.serialFilter) that stops devoted lessons from being deserialized,” says Onapsis.

One other critical-severity subject resolved on Tuesday is CVE-2025-42937 (CVSS rating of 9.8), a listing traversal bug in Print Service, which may enable unauthenticated attackers to overwrite system information.

SAP additionally rolled out patches for CVE-2025-42910 (CVSS rating of 9.0), an unrestricted file add defect in Provider Relationship Administration (SRM) that would enable authenticated attackers to add arbitrary information, together with executables containing malware.

This month, SAP printed two safety notes addressing high-severity vulnerabilities. The primary resolves CVE-2025-5115, a denial-of-service (DoS) bug in Commerce Cloud, whereas the second fixes CVE-2025-48913, a safety misconfiguration flaw in Information Hub Integration Suite.Commercial. Scroll to proceed studying.

The remaining 10 new and up to date safety notes resolve medium- and low-severity defects in NetWeaver, ABAP, Commerce Cloud, S/4HANA, Monetary Service Claims Administration, BusinessObjects, and Cloud Equipment.

After the scheduled month-to-month patch day, SAP up to date its September 2025 advisory with one new and 7 up to date safety notes, together with three coping with critical-severity vulnerabilities.

SAP makes no point out of any of those points being exploited within the wild, however customers are suggested to use the patches and mitigations as quickly as doable. Menace actors are identified to have focused SAP bugs of their assaults.

Associated: New Exploit Poses Menace to SAP NetWeaver Situations

Associated: Crucial Vulnerability Patched in SAP NetWeaver

Associated: Oracle Patches EBS Vulnerability Permitting Entry to Delicate Information

Associated: Juniper Networks Patches Crucial Junos Area Vulnerabilities

Security Week News Tags:Critical, NetWeaver, Patches, Print, SAP, Service, SRM, Vulnerabilities

Post navigation

Previous Post: Fraud Prevention Firm Resistant AI Raises $25 Million
Next Post: Thousands of North Korean IT Workers Using VPNs and ‘Laptop Farms’ to Bypass Origin Verification

Related Posts

Cyber Insights 2026: Regulations and the Tangled Mess of Compliance Requirements Cyber Insights 2026: Regulations and the Tangled Mess of Compliance Requirements Security Week News
WhatsApp Takes Down 6.8 Million Accounts Linked to Criminal Scam Centers, Meta Says WhatsApp Takes Down 6.8 Million Accounts Linked to Criminal Scam Centers, Meta Says Security Week News
Critical Authentication Bypass Flaw Patched in Teleport Critical Authentication Bypass Flaw Patched in Teleport Security Week News
British Department Store Harrods Warns Customers That Some Personal Details Taken in Data Breach British Department Store Harrods Warns Customers That Some Personal Details Taken in Data Breach Security Week News
Cyber Insights 2026: Threat Hunting in an Age of Automation and AI Cyber Insights 2026: Threat Hunting in an Age of Automation and AI Security Week News
2024 VMware Flaw Now in Attackers’ Crosshairs 2024 VMware Flaw Now in Attackers’ Crosshairs Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages
  • DragonForce Ransomware Group’s Expanding Cartel Operations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages
  • DragonForce Ransomware Group’s Expanding Cartel Operations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News