SAP has released security updates addressing 13 newly identified vulnerabilities across its product suite, with particular focus on a maximum-severity flaw in SAP NetWeaver AS Java. The most critical vulnerability, tracked as CVE-2025-42944 and assigned a CVSS score of 10.0, is an insecure deserialization issue that allows unauthenticated attackers to execute arbitrary operating system commands. This flaw can be exploited via the RMI-P4 module by submitting a malicious payload to an open port, potentially compromising the confidentiality, integrity, and availability of affected systems. SAP initially addressed this vulnerability in a previous update, but the latest patch introduces additional hardening measures, including a JVM-wide filter (jdk.serialFilter) to block the deserialization of dangerous classes. The list of classes and packages to be filtered was developed in collaboration with the Onapsis Research Labs and is divided into mandatory and optional sections to maximize protection. In addition to CVE-2025-42944, SAP has patched a directory traversal vulnerability in SAP Print Service (CVE-2025-42937, CVSS 9.8), which could allow unauthenticated attackers to overwrite system files by exploiting insufficient path validation. Another critical issue, CVE-2025-42910 (CVSS 9.0), affects SAP Supplier Relationship Management and involves unrestricted file upload, enabling authenticated attackers to upload arbitrary files, including potentially malicious executables. These vulnerabilities collectively pose significant risks to enterprise environments running SAP solutions, as successful exploitation could lead to system compromise, data loss, or service disruption. SAP has stated that there is currently no evidence of these vulnerabilities being exploited in the wild. Security experts and SAP have emphasized the importance of promptly applying the latest patches to mitigate the risk of exploitation. The additional hardening for the deserialization flaw is particularly notable, as it provides a more robust defense against a class of attacks that have historically been difficult to fully remediate. Organizations are advised to review their SAP deployments, ensure all relevant updates are applied, and follow SAP’s guidance on blocking risky deserialization classes. The disclosure and remediation of these vulnerabilities highlight the ongoing challenges in securing complex enterprise software platforms. SAP’s collaboration with security researchers and the implementation of layered defenses demonstrate a proactive approach to addressing critical security issues. Enterprises relying on SAP NetWeaver and related products should prioritize these updates as part of their regular patch management processes. Failure to address these vulnerabilities could leave systems exposed to remote attacks that require no authentication, significantly increasing the risk profile for affected organizations. The security community continues to monitor for any signs of exploitation and urges vigilance in maintaining up-to-date SAP environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The same patch release fixed CVE-2025-42937, a directory traversal flaw in SAP Print Service rated CVSS 9.8, and CVE-2025-42910, an unrestricted file upload bug in SAP Supplier Relationship Management rated CVSS 9.0. Reports said there was no evidence of in-the-wild exploitation at the time of disclosure.
SAP patched CVE-2025-42944, a maximum-severity insecure deserialization flaw in the RMI-P4 module of SAP NetWeaver AS Java that could allow unauthenticated attackers to execute arbitrary OS commands and take over servers. SAP also added a JVM-wide filter with mandatory and optional class/package blocks to reduce dangerous deserialization exposure.
SAP issued security updates for 13 newly disclosed flaws, including fixes for SAP NetWeaver AS Java, SAP Print Service, and SAP Supplier Relationship Management. The release addressed multiple high-severity issues and included additional hardening measures for deserialization risks in AS Java environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.