Watch out – this SAP NetWeaver bug has a maximum severity score, and it could target your servers next

  • SAP patched CVE-2025-42944, a critical flaw allowing unauthenticated OS command execution
  • Two more severe vulnerabilities affect SAP Print Service and Supplier Relationship Management modules
  • Unpatched systems remain exposed; n-day flaws are widely exploited due to delayed patching

Software giant SAP released additional security hardening for a maximum-severity vulnerability that grants threat actors arbitrary command execution capabilities on compromised endpoints.

Earlier this week, the company published a new security advisory, detailing fixes for a total of 17 vulnerabilities (13 fixes and 4 updates), including a 10/10 “insecure deserialization in SAP NetWeaver AS Java” flaw. Tracked as CVE-2025-42944, the flaw allowed threat actors to exploit systems through the RMI-P4 module by submitting malicious payloads to an open port.

“The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high impact to the application’s confidentiality, integrity, and availability,” NVD explained. SAP patched it as part of its September 2025 Security Patch Day.

Abusing n-days

The advisory details two additional critical-severity flaws, a “directory traversal vulnerability” in SAP Print Service, and an “unrestricted file upload vulnerability” in SAP Supplier Relationship Management.

The former is tracked as CVE-2025-42937 and has a severity score of 9.8/10, while the latter is tracked as CVE-2025-42910, and has a severity score of 9.0/10.

While none of these bugs were seen being abused in the wild by threat actors, SAP urges its users to apply the patches and mitigations as soon as possible, to minimize any potential risks.

Exploits for zero-day flaws are arguably more successful compared to n-day ones, but n-day vulnerabilities are abused a lot more frequently. This is due to the fact that many organizations fail to patch their systems on time, leaving exposed instances connected to the wider internet for months on end.

This, paired with widely available Proof-of-concept (PoC) exploits, often makes n-day flaws low-hanging fruit that is easy to exploit.

SAP is the world’s largest ERP vendor, with products in use by more than 90% of the Forbes Global 2000 list, so cybercriminals will most likely scan for endpoints that haven’t applied the patch, looking for a way into the IT networks of some of the world’s most important brands.

Via The Hacker News

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Read more @ TechRadar

Latest posts

WhatsApp is launching third-party chat integration in Europe

Meta is on the cusp of launching third-party integration with WhatsApp in Europe — something that’s required by the Digital Markets Act (DMA). It’s...

Why “old” data is the new gold in the age of AI

Isn't old data just big data in new clothes?AI innovation is driving exponential growth in the volume and value of data. More specifically, Generative...

I compared GPT-5.1 to GPT-5 on ChatGPT, and now I don’t want to go back

Some ChatGPT users greeted the introduction of GPT-5.1 as the default model for the chatbot with some skepticism – after all, more than a...

Procurement in 2025: Building foundations for strategic supplier relationships in a changing world

In a rapidly evolving global landscape, procurement is no longer simply concerned with cost savings and efficiency. Now, building resilient partnerships and maintaining shared...

Call Recording is rolling out to some Google Pixel phones now – here’s how to use it

Call Recording is rolling out to the Pixel 6 and newerThis feature is coming to phones that don't support Call NotesIt allows you to...

The new age of layered security: from supply chains to endpoints

A 2025 global survey found that 72% of business leaders have witnessed a recent rise in cyber risks. Simultaneously, organizations face a shortage of...

Missed out on Netflix’s Stranger Things season 5 episode 1 screening? I asked lucky fans why we’re ‘not ready’ to return to the Upside...

If you live in London, UK, and happened to be free yesterday (November 13) at almost midnight, you stood a chance of grabbing extremely...

The Arc Raiders devs are tweaking the community unlock event due to players being too generous with donations – ‘We had no idea all...

Arc Raiders players are currently working together to unlock a new mapDeveloper Embark Studios has praised players for progressing so quickly towards the goalThe...

Man of Tomorrow will reportedly feature a classic Superman foe – now it’s time for James Gunn to comment on the worst-kept secret in...

Man of Tomorrow's primary villain has apparently been revealedIt's someone who's been long rumored to appear in the DCU movieJames Gunn is yet to...

Software makers say piracy is becoming a bigger problem than ever before – so what can be done?

Software piracy is big in China, Russia and India – and growing in GermanyMany track telemetry but do nothing with it, reducing observabilityClear functional...