Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

SAP Patches Critical S/4HANA Vulnerability

SAP has released 15 new security notes on the August 2025 Patch Tuesday, including for critical vulnerabilities.

SAP

SAP has fixed more than a dozen vulnerabilities with its August 2025 Patch Tuesday updates, including critical vulnerabilities. 

This Patch Tuesday — or as the enterprise software giant calls it, Security Patch Day — 15 new security notes (fixes) have been released, along with four updates to previous fixes.

Onapsis, a company specializing in enterprise application security, which often finds SAP product vulnerabilities, pointed out that the vendor has released a total of 26 new and updated fixes since the previous Patch Tuesday.

Of these 26 fixes, four have been classified as ‘hot news’ or ‘critical’, including two that are new and two updates to previous patches. The new ‘hot news’ patches are for CVE-2025-42950 and CVE-2025-42957, which have been described as code injection issues.

According to Onapsis, they can be exploited for arbitrary code execution, which can lead to a full system compromise. 

CVE-2025-42950 and CVE-2025-42957 are the same vulnerability, Onapsis said, but different CVEs have been assigned to different products. CVE-2025-42957 has been assigned to the S/4HANA enterprise resource planning (ERP) software, while CVE-2025-42950 is for the older generation of the ERP software, ERP Central Component (ECC). 

Advertisement. Scroll to continue reading.

The new high-priority patches address a broken authorization issue in SAP Business One (CVE-2025-42951, allows an authenticated attacker to obtain admin privileges), and multiple memory corruption bugs in NetWeaver Application Server ABAP (CVE-2025-42976, can lead to sensitive information leaks).

The remaining new issues, which have ‘low’ or ‘medium’ priority, impact S/4HANA, NetWeaver, ABAP Platform, Cloud Connector and other products.

It’s important for organizations to install the available updates as it’s not uncommon for threat actors to exploit SAP product vulnerabilities in their attacks. 

SAP customers were recently warned that a NetWeaver zero-day flaw patched in April had been exploited since at least January. NetWeaver vulnerabilities have been exploited recently by both ransomware groups and cyberspies

Related: SAP Patches Critical Flaws That Could Allow Remote Code Execution, Full System Takeover

Related: Critical Vulnerability Patched in SAP NetWeaver

Related: SAP Patches Another Exploited NetWeaver Vulnerability

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.