SAP fixes serious security issues – here’s how to stay safe

  • CVE-2025-42887 in SAP Solution Manager allows unauthenticated code injection and full system takeover
  • Vulnerability scored 9.9/10; patch released in SAP’s November 2025 update
  • SAP also fixed CVE-2024-42890, a 10/10 flaw in SQL Anywhere Monitor

SAP Solution Manager, an application lifecycle management (ALM) platform with tens of thousands of user organizations, carried a critical severity vulnerability that allowed threat actors to fully take over compromised endpoints, experts have warned.

Security researchers SecurityBridge, who notified SAP after finding the flaw, described as a “missing input sanitation” vulnerability, which allows unauthenticated threat actors to insert malicious code when calling a remote-enabled function module.

“This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system”, the National Vulnerability Database (NVD) explained.

SAP fixes a 10/10 bug

The bug is now tracked as CVE-2025-42887 and was given a severity score of 9.9/10 (critical).

A patch is now publicly available, and while SAP’s users were previously notified, the researchers are once again urging everyone to apply it as soon as possible since the risk is only going to get bigger going forward:

“A public patch for this vulnerability has been released today, which might speed up reverse-engineering and exploit development, so patching soon is advised,” SecurityBridge said in its announcement.

“When we discover a vulnerability that scores a 9.9 out of 10 priority rating, we know we’re looking at a threat that could give attackers complete system control,” said Joris van de Vis, Director of Security Research, SecurityBridge.

“CVE-2025-42887 is particularly dangerous because it allows to inject code from a low-privileged user, which leads to a full SAP compromise and all data contained in the SAP system. This code-injection vulnerability in SAP Solution Manager represents exactly the kind of critical attack surface weakness that our Threat Research Labs work tirelessly to identify and eliminate. SAP systems are the backbone of business operations, and vulnerabilities like this remind us why proactive security research is non-negotiable.”

The vulnerability was fixed as part of SAP’s November Patch Day, a cumulative update that addressed 18 new and updates to two previously observed bugs. Besides the one mentioned above, SAP fixed a 10/10 flaw in the non-GUI variant of the SQL Anywhere Monitor. This bug is tracked as CVE-2024-42890 and is another case of hardcoded credentials.

“SQL Anywhere Monitor (Non-GUI) baked credentials into the code, exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution,” the description reads. SQL Anywhere Monitor is a database monitoring and alert tool, and part of the SQL Anywhere suite.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

The Clapper was a bad smart home gadget — and a viral sensation

Clap on. Clap off. Well, more like, Clap, pause for half a beat but no longer because otherwise it'll stop hearing you, clap again...

US Marshals arrest the Tate brothers in Miami

Andrew and Tristan Tate talk to the media on March 23, 2025 in Romania. | Image: Andrei Pungovschi/Getty Images The manosphere influencers Andrew and Tristan...

Birdfy’s solar-powered smart feeder is down to one of its best prices

It comes with a solar panel so you don’t need to worry about charging as much during the summer. | Image: Netvue Birdfy has kicked...

Orchid is a delightfully retro and approachable hipster synth

A modern tribute to electric chord organs which were basically giant harmonicas connected to a fan. | Photo: Terrence O’Brien / The Verge In 2017,...

OnePlus died with a whimper, not a bang

OnePlus is dead – actually for real this time. It’s got me looking back on my experiences with the brand’s smartphones, the absolute roller...

The grueling, 630-mile road race where the only fuel is sunlight

The 2018 Solar Car Challenge was the last time participants took their designs out on the open road. | Image: Lehman Marks / Solar...

The future of physical games is not looking great

Grand Theft Auto VI release won’t offer a disc. | Image: Rockstar Games This is The Stepback, a weekly newsletter breaking down one essential story...

Dave Eggers told OpenAI staff that ChatGPT was ‘silencing an entire generation’

Dave Eggers attends the "The Turning Point: To Be Destroyed" premiere. | Image: John Lamparski/Getty Images for Tribeca Festival Last year, Sam Altman invited author...

YouTube picture-in-picture (PiP) mode is broken on iPhone, Android

YouTube is aware of an issue on Android and iPhone where picture-in-picture (PiP) mode does not activate when closing the app. Read more @ 9to5google

Galaxy Watch 9 is ‘Powered by Snapdragon Wear Elite,’ leaked images confirm [Gallery]

As expected, Samsung is switching its new Galaxy Watch 9 over to a Qualcomm chip, the Snapdragon Wear Elite, as some new images confirm....