Vulnerabilities

SAP Patches Critical Flaws in SQL Anywhere Monitor, Solution Manager

Hardcoded credentials in SQL Anywhere Monitor could allow attackers to execute arbitrary code on vulnerable deployments.

SAP

Enterprise software maker SAP on Tuesday announced the release of 18 new and one updated security note as part of its November 2025 security patches.

The most important of SAP’s November 2025 notes deals with CVE-2025-42890 (CVSS score of 10/10), described as an insecure key and secret management vulnerability in SQL Anywhere Monitor.

The bug exists because hardcoded credentials in SQL Anywhere Monitor could be exploited to execute arbitrary code on the affected systems, impacting system confidentiality, integrity, and availability.

To resolve the issue, SAP removed SQL Anywhere Monitor entirely, according to enterprise application security firm Onapsis.

“As a temporary workaround, SAP recommends to stop using SQL Anywhere Monitor and to delete any instances of SQL Anywhere Monitor database,” Onapsis notes.

On Tuesday, SAP also rolled out fixes for CVE-2025-42887 (CVSS score of 9.9), a critical-severity code injection defect in Solution Manager. The flaw exists because a remote-enabled function module did not sanitize user input, allowing attackers to inject malicious code.

Advertisement. Scroll to continue reading.

Additionally, the software maker updated a security note released on October 2025 Security Patch Day to harden protections against recent insecure deserialization flaws in NetWeaver AS Java. The note tackles CVE-2025-42944, a security defect with a CVSS score of 10/10.

SAP’s fresh patches also resolve CVE-2025-42940 (CVSS score of 7.5), a high-severity memory corruption vulnerability in CommonCryptoLib.

“Missing boundary checks enable an attacker to send malicious data which could result in memory corruption followed by an application crash,” Onapsis explains.

The remaining notes released on SAP’s November 2025 Security Patch Day address medium- and low-severity bugs in HANA JDBC Client, Business Connector, NetWeaver, S/4HANA landscape, HANA 2.0, SAP GUI for Windows, Starter Solution, Business One, and S4CORE.

Between the October and November patches, SAP rolled out updates for six security notes, including an October 2025 note that addresses a critical-severity unrestricted file upload issue in Supplier Relationship Management.

Tracked as CVE-2025-42910 (CVSS score of 9.0), the defect could allow authenticated attackers to upload potentially malicious files. The updated note contains extended validity information.

SAP makes no mention of any of the patched vulnerabilities being exploited in the wild. Users are advised to apply the security notes as soon as possible, as SAP flaws are a popular target for threat actors.

Related: QNAP Patches Vulnerabilities Exploited at Pwn2Own Ireland

Related: Chrome 142 Update Patches High-Severity Flaws

Related: Cisco Patches Critical Vulnerabilities in Contact Center Appliance

Related: Apple Patches 19 WebKit Vulnerabilities

Related Content

Vulnerabilities

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

Vulnerabilities

A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

Vulnerabilities

Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.

Vulnerabilities

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Mobile & Wireless

The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.

Vulnerabilities

Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version