Tag: sap
-
SAP zero-day wake-up call: Why ERP systems need a unified defense
In this Help Net Security video, Paul Laudanski, Director of Research at Onapsis, discusses key lessons from the SAP zero-day vulnerability. He explains why business-critical … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/10/17/sap-zero-day-security-video/
-
SAP zero-day wake-up call: Why ERP systems need a unified defense
In this Help Net Security video, Paul Laudanski, Director of Research at Onapsis, discusses key lessons from the SAP zero-day vulnerability. He explains why business-critical … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/10/17/sap-zero-day-security-video/
-
Frightful Patch Tuesday gives admins a scare with 175+ Microsoft CVEs, 3 under attack
Plus: Adobe, SAP, Ivanti offer treats, not tricks First seen on theregister.com Jump to article: www.theregister.com/2025/10/14/microsoft_october_2025_patch_tuesday/
-
SAP Patchday Oktober 2025 10.0-Schwachstelle in SAP Netweaver wird erneut gepatcht
First seen on security-insider.de Jump to article: www.security-insider.de/sap-patchday-oktober-2025-netweaver-updates-a-293e84f7bbc70e6f65cf25c84b1d65b0/
-
SAP fixed maximum-severity bug in NetWeaver
SAP addressed 13 new flaws, including a maximum severity vulnerability in SAP NetWeaver, which could lead to arbitrary command execution. SAP addressed 13 new vulnerabilities, including a maximum severity issue, tracked as CVE-2025-42944 (CVSS score of 10.0) in SAP NetWeaver. The vulnerability is an insecure deserialization that could lead to arbitrary command execution. >>Due to a deserialization…
-
New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login
SAP has rolled out security fixes for 13 new security issues, including additional hardening for a maximum-severity bug in SAP NetWeaver AS Java that could result in arbitrary command execution.The vulnerability, tracked as CVE-2025-42944, carries a CVSS score of 10.0. It has been described as a case of insecure deserialization.”Due to a deserialization vulnerability in…
-
New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login
SAP has rolled out security fixes for 13 new security issues, including additional hardening for a maximum-severity bug in SAP NetWeaver AS Java that could result in arbitrary command execution.The vulnerability, tracked as CVE-2025-42944, carries a CVSS score of 10.0. It has been described as a case of insecure deserialization.”Due to a deserialization vulnerability in…
-
New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login
SAP has rolled out security fixes for 13 new security issues, including additional hardening for a maximum-severity bug in SAP NetWeaver AS Java that could result in arbitrary command execution.The vulnerability, tracked as CVE-2025-42944, carries a CVSS score of 10.0. It has been described as a case of insecure deserialization.”Due to a deserialization vulnerability in…
-
SAP NetWeaver Memory Corruption Flaw Lets Attackers Send Corrupted Logon Tickets
A newly disclosed vulnerability in SAP NetWeaver AS ABAP and ABAP Platform (CVE-2025-42902) allows unauthenticated attackers to crash server processes by sending malformed SAP Logon or SAP Assertion Tickets. RatedMediumseverity with a5.3CVSS 3.1 score, the flaw stems from a NULL pointer dereference that triggers memory corruption and process termination. Affected versions include all supported releases…
-
SAP NetWeaver Memory Corruption Flaw Lets Attackers Send Corrupted Logon Tickets
A newly disclosed vulnerability in SAP NetWeaver AS ABAP and ABAP Platform (CVE-2025-42902) allows unauthenticated attackers to crash server processes by sending malformed SAP Logon or SAP Assertion Tickets. RatedMediumseverity with a5.3CVSS 3.1 score, the flaw stems from a NULL pointer dereference that triggers memory corruption and process termination. Affected versions include all supported releases…
-
SAP NetWeaver Memory Corruption Flaw Lets Attackers Send Corrupted Logon Tickets
A newly disclosed vulnerability in SAP NetWeaver AS ABAP and ABAP Platform (CVE-2025-42902) allows unauthenticated attackers to crash server processes by sending malformed SAP Logon or SAP Assertion Tickets. RatedMediumseverity with a5.3CVSS 3.1 score, the flaw stems from a NULL pointer dereference that triggers memory corruption and process termination. Affected versions include all supported releases…
-
Boomi führt Change Data Capture für SAP-Daten ein Echtzeit-Einblicke für die agentische Transformation
SAP-Kunden können nun in Echtzeit auf Daten aus ECC, S/4HANA und BW zugreifen ohne Code und mit integrierter CDC für intelligentere Entscheidungen in KI und Analytics First seen on infopoint-security.de Jump to article: www.infopoint-security.de/boomi-fuehrt-change-data-capture-fuer-sap-daten-ein-echtzeit-einblicke-fuer-die-agentische-transformation/a42303/
-
SAP-Kunden: Anforderungen nach Souveränität werden immer stärker
Tags: sapAngesichts einer unsicheren Weltlage wollen SAP-Kunden aller Branchen mehr Souveränität. Golem hat auf der SAP Connect in Las Vegas nachgefragt. First seen on golem.de Jump to article: www.golem.de/news/sap-kunden-anforderungen-nach-souveraenitaet-werden-immer-staerker-2510-200848.html
-
EU probes SAP over anti-competitive ERP support practices
The European Comission is investigating potential anti-competitive practices in aftermarket services SAP provides for its on-premise ERP software. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/legal/eu-probes-sap-over-anti-competitive-erp-support-practices/
-
Jaguar Land Rover nach Cyberattacke weiter lahmgelegt
Ein Cyberangriff auf den britischen Autohersteller Jaguar Land Rover hat zu einem Produktionsstopp geführt.Der britische Automobilhersteller Jaguar Land Rover hat wegen einer Cyberattacke Anfang September 2025 schwere Störungen bei Produktion und Verkauf hinnehmen müssen.Wie das Unternehmen damals mitteilte, wurden die Systeme heruntergefahren, um den Schaden zu begrenzen. “Wir arbeiten jetzt rasch daran, um unsere weltweit…
-
SAP Patchday September 2025 – Einfach ausnutzbare Schwachstelle in SAP Netweaver CVSS 10.0
First seen on security-insider.de Jump to article: www.security-insider.de/sap-patchday-september-2025-netweaver-updates-a-e69ad257d378b5c5894c836edda50797/
-
SAP Issues Critical Security Patch for NetWeaver and Other Products, Warns of CVE-2025-42944
SAP has released a new security update addressing a broad range of vulnerabilities across its product ecosystem. Among the most alarming is a critical vulnerability identified in SAP NetWeaver, tracked as CVE-2025-42944, which has received the highest possible severity rating of CVSS 10.0. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/sap-patches-cve-2025-42944/
-
SAP warns of high-severity vulnerabilities in multiple products
Users of SAP’s S/4HANA and NetWeaver products are at risk and should patch soon. First seen on arstechnica.com Jump to article: arstechnica.com/security/2025/09/as-hackers-exploit-one-high-severity-sap-flaw-company-warns-of-3-more/
-
This Patch Tuesday, SAP is the worst offender and Microsoft users can kinda chill
ERP giant patches flaw that allows total takeover of NetWeaver, Microsoft has nothing under attack for once First seen on theregister.com Jump to article: www.theregister.com/2025/09/10/microsoft_patch_tuesday/
-
SAP September 2025 Patch Day fixed 4 critical flaws
SAP issues 21 new and 4 updated security notes, fixing critical NetWeaver flaws enabling RCE and privilege escalation. SAP this week issued 21 new and four updated security notes as part of the company’s September Patch Day, including four notes that address critical vulnerabilities in NetWeaver. Onapsis Research Labs supported SAP in patching two critical…
-
Microsoft, Adobe, SAP deliver critical fixes for September 2025 Patch Tuesday
On September 2025 Patch Tuesday, Microsoft has released patches for 80+ vulnerabilities in its various software products, but the good news is that none of them are actively … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/09/10/microsoft-adobe-sap-deliver-critical-fixes-for-september-2025-patch-tuesday/
-
SAP Patches Critical NetWeaver (CVSS Up to 10.0) and High-Severity S/4HANA Flaws
SAP on Tuesday released security updates to address multiple security flaws, including three critical vulnerabilities in SAP Netweaver that could result in code execution and the upload arbitrary files.The vulnerabilities are listed below -CVE-2025-42944 (CVSS score: 10.0) – A deserialization vulnerability in SAP NetWeaver that could allow an unauthenticated attacker to submit a malicious First…
-
As hackers exploit one high-severity SAP flaw, company warns of 3 more
Users of SAP’s S/4HANA and NetWeaver products are at risk and should patch soon. First seen on arstechnica.com Jump to article: arstechnica.com/security/2025/09/as-hackers-exploit-one-high-severity-sap-flaw-company-warns-of-3-more/
-
SAP fixes maximum severity NetWeaver command execution flaw
SAP has addressed 21 new vulnerabilities affecting its products, including three critical severity issues impacting the NetWeaver software solution. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sap-fixes-maximum-severity-netweaver-command-execution-flaw/
-
SAP fixes maximum severity NetWeaver command execution flaw
SAP has addressed 21 new vulnerabilities affecting its products, including three critical severity issues impacting the NetWeaver software solution. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sap-fixes-maximum-severity-netweaver-command-execution-flaw/
-
SAP fixes maximum severity NetWeaver command execution flaw
SAP has addressed 21 new vulnerabilities affecting its products, including three critical severity issues impacting the NetWeaver software solution. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sap-fixes-maximum-severity-netweaver-command-execution-flaw/
-
SAP Security Patch Day Addresses 21 Vulnerabilities, 4 Classified as Critical
SAP’s Security Patch Day on September 9, 2025, introduced fixes for 21 newly discovered vulnerabilities across its product portfolio and provided updates to four previously released security notes. With four issues rated asCritical, organizations running SAP environments are urged to prioritize patching to safeguard their systems from potential exploits. This month’s release spans a variety…
-
SAP S/4HANA Users Urged to Patch Critical Exploited Bug
Critical SAP S/4HANA vulnerability CVE-2025-42957 is being exploited in the wild First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/sap-s4hana-patch-critical/

