Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CloudAI-assisted

SAP Security Patch Day Addresses 21 Vulnerabilities, 4 Classified as Critical

Cybersecurity On Tue, Sep 9, 2025, SAP released security patches addressing 21 new vulnerabilities within its product suite, along with updates to four previously issued security notes. Among these, four vulnerabilities are classified as Critical . Organizations utilizing SAP systems…

SAP Security Patch Day Addresses 21 Vulnerabilities, 4 Classified as Critical

Cybersecurity

On Tue, Sep 9, 2025, SAP released security patches addressing 21 new vulnerabilities within its product suite, along with updates to four previously issued security notes.

Among these, four vulnerabilities are classified as Critical. Organizations utilizing SAP systems are advised to prioritize applying these patches to mitigate potential security risks.

This security update encompasses a range of SAP products, including NetWeaver components, ABAP platforms, S/4HANA, and Business One modules.

The vulnerabilities rated as Critical have a CVSS score of 9.0 or higher, indicating a significant impact on confidentiality, integrity, and availability if not promptly addressed.

SAP also refined or expanded patches for four earlier security notes, enhancing existing security measures.

Organizations utilizing SAP systems are advised to prioritize applying these patches to mitigate potential security risks.
William Hayes · Thehackingpost

Details on the security notes and necessary updates can be accessed through the SAP Support Portal. Customers are strongly recommended to implement these updates without delay.

Vulnerability Details

The Critical vulnerabilities include issues such as insecure deserialization in SAP NetWeaver, insecure file operations in AS Java, directory traversal in ABAP platforms, and missing authentication checks in NetWeaver kernels.

High-severity vulnerabilities primarily involve missing input validation or insecure storage, impacting modules like Business One, S/4HANA replication, and SAP Landscape Transformation servers.

Advertisement

Medium-rated vulnerabilities involve misconfigurations, cross-site scripting, and missing authorization checks in HCM Fiori apps, Commerce Cloud, and Business Planning modules.

Low-rated vulnerabilities address reverse tabnabbing in Fiori launchpads, outdated OpenSSL in Adobe Document Services, and a historical vulnerability in Commerce Cloud.

CVE(s) Title Priority CVSS
CVE-2025-42944Insecure DeserializationCritical10.0
CVE-2025-42922Insecure File OperationsCritical9.9
CVE-2023-27500Directory TraversalCritical9.6
CVE-2025-42958Missing Authentication checkCritical9.1
CVE-2025-42933Insecure Storage of Sensitive InformationHigh8.8
CVE-2025-42929Missing input validationHigh8.1
CVE-2025-42916Missing input validationHigh8.1
CVE-2025-27428Directory TraversalHigh7.7
CVE-2025-22228Security MisconfigurationMedium6.6
CVE-2025-42930Denial of ServiceMedium6.5
CVE-2025-42912, 42913, 42914Missing Authorization checkMedium6.5
CVE-2025-42917Missing Authorization checkMedium6.5
CVE-2023-5072Denial of Service (outdated JSON library)Medium6.5
CVE-2025-42920Cross-Site ScriptingMedium6.1
CVE-2025-42938Cross-Site ScriptingMedium6.1
CVE-2025-42915Missing Authorization CheckMedium5.4
CVE-2025-42926Missing Authentication checkMedium5.3
CVE-2025-42911Missing Authorization checkMedium5.0
CVE-2025-42961Missing Authorization checkMedium4.9
CVE-2025-42925Predictable Object IdentifierMedium4.3
CVE-2025-42923Cross-Site Request ForgeryMedium4.3
CVE-2025-42918Missing Authorization checkMedium4.3
CVE-2025-42941Reverse TabnabbingLow3.5
CVE-2025-42927Information Disclosure (Outdated OpenSSL)Low3.4
CVE-2024-13009Improper Resource ReleaseLow3.1

For secure configuration guidance and detailed vulnerability information, customers can consult the SAP Support portal and official documentation.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories