Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

SAP Patches Critical Vulnerabilities in NetWeaver, Print Service, SRM

SAP has rolled out additional protections for insecure deserialization bugs resolved in NetWeaver AS Java recently.

SAP

Business software maker SAP on Tuesday announced the release of 16 new and updated patch notes as part of its monthly rollout, including three fresh notes that address critical-severity vulnerabilities.

One of the patches released on October 2025 Security Patch Day resolves once again CVE-2025-42944 (CVSS score of 10/10), described as an insecure deserialization flaw in NetWeaver AS Java.

According to enterprise software security firm Onapsis, the security note adds fresh protections to insecure deserialization flaws resolved in NetWeaver over the past months, including CVE-2025-42944, which was initially patched in September 2025.

In fact, SAP also updated the September 2025 security note dealing with CVE-2025-42944, to add a reference to the newly released hardening recommendations.

“The additional layer of protection is based on implementing a JVM-wide filter (jdk.serialFilter) that prevents dedicated classes from being deserialized,” says Onapsis.

Another critical-severity issue resolved on Tuesday is CVE-2025-42937 (CVSS score of 9.8), a directory traversal bug in Print Service, which could allow unauthenticated attackers to overwrite system files.

Advertisement. Scroll to continue reading.

SAP also rolled out patches for CVE-2025-42910 (CVSS score of 9.0), an unrestricted file upload defect in Supplier Relationship Management (SRM) that could allow authenticated attackers to upload arbitrary files, including executables containing malware.

This month, SAP published two security notes addressing high-severity vulnerabilities. The first resolves CVE-2025-5115, a denial-of-service (DoS) bug in Commerce Cloud, while the second fixes CVE-2025-48913, a security misconfiguration flaw in Data Hub Integration Suite.

The remaining 10 new and updated security notes resolve medium- and low-severity defects in NetWeaver, ABAP, Commerce Cloud, S/4HANA, Financial Service Claims Management, BusinessObjects, and Cloud Appliance.

After the scheduled monthly patch day, SAP updated its September 2025 advisory with one new and seven updated security notes, including three dealing with critical-severity vulnerabilities.

SAP makes no mention of any of these issues being exploited in the wild, but users are advised to apply the patches and mitigations as soon as possible. Threat actors are known to have targeted SAP bugs in their attacks.

Related: New Exploit Poses Threat to SAP NetWeaver Instances

Related: Critical Vulnerability Patched in SAP NetWeaver

Related: Oracle Patches EBS Vulnerability Allowing Access to Sensitive Data

Related: Juniper Networks Patches Critical Junos Space Vulnerabilities

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

Quantum Secure Encryption has named Michael Massing as Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.