Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      CodeSOD: The Getter Setter Getter

      September 12, 2025

      Low-Code vs No-Code Platforms for Node.js: What CTOs Must Know Before Investing

      September 12, 2025

      ServiceNow unveils Zurich AI platform

      September 12, 2025

      Integrating CSS Cascade Layers To An Existing Project

      September 11, 2025

      Distribution Release: GLF OS 25.05

      September 10, 2025

      Your guide to GitHub Universe 2025: The schedule just launched!

      September 10, 2025

      What’re Your Top 4 CSS Properties?

      September 10, 2025

      Distribution Release: Univention Corporate Server 5.2-3

      September 10, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Modernizing on Your Own Terms: A Strategic Guide to Managing Node.js Legacy Systems

      September 11, 2025
      Recent

      Modernizing on Your Own Terms: A Strategic Guide to Managing Node.js Legacy Systems

      September 11, 2025

      External Forces Reshaping Financial Services in 2025 and Beyond

      September 10, 2025

      Why It’s Time to Move from SharePoint On-Premises to SharePoint Online

      September 10, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Pironman 5 Max Review: Best Raspberry Pi Case Money can Buy

      September 12, 2025
      Recent

      Pironman 5 Max Review: Best Raspberry Pi Case Money can Buy

      September 12, 2025

      FOSS Weekly #25.37: Mint 22.2 Released, Official KDE Distro, Kazeta Linux for 90s Gaming, Ubuntu 25.10’s New Terminal and More Linux Stuff

      September 11, 2025

      Distribution Release: GLF OS 25.05

      September 10, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»SAP Issues Critical Security Patch for NetWeaver and Other Products, Warns of CVE-2025-42944

    SAP Issues Critical Security Patch for NetWeaver and Other Products, Warns of CVE-2025-42944

    September 12, 2025

    CVE-2025-42944

    SAP has released a new security update addressing a broad range of vulnerabilities across its product ecosystem. Among the most alarming is a critical vulnerability identified in SAP NetWeaver, tracked as CVE-2025-42944, which has received the highest possible severity rating of CVSS 10.0.  

    This particular flaw allows unauthenticated attackers to execute arbitrary commands remotely, posing a significant threat to enterprise systems running the affected software. 

    Decoding SAP CVE-2025-42944 Vulnerability 

    According to SAP’s September 2025 Security Patch Day bulletin, CVE-2025-42944 stems from an insecure deserialization vulnerability within the Remote Method Invocation Protocol (RMI-P4) of SAP NetWeaver SERVERCORE version 7.50.  

    This vulnerability enables threat actors to deliver specially crafted payloads through an open port, which the system then deserializes and executes, potentially giving attackers full control over the targeted system. 

    Deserialization is the process of converting data back into an object after it has been serialized for storage or transmission. Improper validation during this process can open the door for serious exploits, such as remote code execution. 

    Additional High-Severity Vulnerabilities in SAP NetWeaver 

    In addition to CVE-2025-42944, SAP disclosed three more high-severity flaws in the same platform: 

    • CVE-2025-42922: An insecure file operations vulnerability in SAP NetWeaver AS Java (Deploy Web Service), rated CVSS 9.9. 
    • CVE-2023-27500: A directory traversal issue previously identified and updated in the March 2023 Patch Day, affecting SAP NetWeaver AS for ABAP and ABAP Platform, with a CVSS score of 9.6. 
    • CVE-2025-42958: A missing authentication check in various SAP NetWeaver kernel versions, rated CVSS 9.1. 

    SAP Security Patch Day

    The September 2025 patch release includes 21 new Security Notes and 5 updates to previously released notes. SAP has urged all customers to prioritize the installation of these patches to mitigate the risk of exploitation. The updates address vulnerabilities in several major SAP products, including SAP S/4HANA, SAP Business One, SAP Commerce Cloud, and SAP HCM, among others. 

    Other Notable Vulnerabilities Patched 

    • CVE-2025-42933: A flaw related to the insecure storage of sensitive data in SAP Business One (SLD), rated CVSS 8.8. 
    • CVE-2025-42929 & CVE-2025-42916: Missing input validation vulnerabilities in the SAP Landscape Transformation Replication Server and SAP S/4HANA, both scored at 8.1. 
    • CVE-2025-27428: A directory traversal issue in SAP NetWeaver and ABAP Platform, updated from the April 2025 Patch Day, rated CVSS 7.7. 
    • CVE-2025-22228: A security misconfiguration in SAP Commerce Cloud and SAP Datahub involving Spring security, with a CVSS score of 6.6. 
    • CVE-2025-42930: A denial-of-service (DoS) vulnerability in SAP Business Planning and Consolidation, scored 6.5. 
    • CVE-2025-42912 to CVE-2025-42914: Multiple missing authorization checks in the SAP HCM My Timesheet Fiori 2.0 application, each rated CVSS 6.5. 
    • CVE-2025-42920 & CVE-2025-42938: Cross-site scripting (XSS) vulnerabilities in SAP Supplier Relationship Management and NetWeaver ABAP Platform, both scored 6.1. 

    Medium and Low-Risk Issues Also Addressed 

    While the most attention-grabbing flaws were rated critical or high, SAP also resolved several medium- and low-severity vulnerabilities: 

    • CVE-2025-42961: An update addressing a missing authorization check in SAP NetWeaver Application Server for ABAP, rated 4.9. 
    • CVE-2025-42941: A reverse tabnabbing vulnerability in SAP Fiori Launchpad, scored 3.5. 
    • CVE-2025-42927: An information disclosure flaw due to outdated OpenSSL versions in SAP NetWeaver AS Java (Adobe Document Service), rated 3.4. 
    • CVE-2024-13009: A potential resource release issue in SAP Commerce Cloud. 

    SAP strongly recommends that all customers log into the SAP Support Portal and apply the necessary security patches immediately to protect their systems. Unpatched vulnerabilities, especially those like CVE-2025-42944, pose a serious risk and can lead to system compromise, data theft, or service disruption. 

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleSenator Wyden Urges FTC to Probe Microsoft for Ransomware-Linked Cybersecurity Negligence
    Next Article FTC Urged to Investigate Microsoft on Outdated RC4 Encryption and Kerberoasting Flaws

    Related Posts

    Development

    AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto

    September 12, 2025
    Development

    Are cybercriminals hacking your systems – or just logging in?

    September 12, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-32470 – Apache HTTP Server DNS Spoofing

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-52841 – Laundry CSRF Account Takeover

    Common Vulnerabilities and Exposures (CVEs)

    CodeSOD: Stop Being So ####

    News & Updates

    🎮 Top PC Games Under 4 GB That Run Smoothly on Any System

    Operating Systems

    Highlights

    News & Updates

    Windows 11 will finally stop nagging you to set Edge as your default browser — but only in some markets

    June 3, 2025

    As part of its continued efforts to make Windows compliant with the Digital Markets Act,…

    CVE-2025-46824 – Discourse Code Review Plugin Cross-Site Scripting (XSS)

    May 7, 2025

    CVE-2025-26416 – LibTIFF SkBmp Standard Codec Heap Buffer Overflow

    September 2, 2025

    CVE-2025-6559 – Sapido Wireless Router OS Command Injection Vulnerability

    June 24, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.