SAP Security Patch Day Fixes Critical Flaws in Solution Manager, NetWeaver & More
SAP has issued its December 2025 Security Patch Day updates, which include 14 new security notes addressing critical and high-severity vulnerabilities across various enterprise products.
SAP has issued its December 2025 Security Patch Day updates, which include 14 new security notes addressing critical and high-severity vulnerabilities across various enterprise products.
CVE-2025-42880: A code injection vulnerability in SAP Solution Manager (ST 720) with a CVSS score of 9.9, allowing low-privileged attackers to execute arbitrary code.
CVE-2025-55754 & CVE-2025-55752: Critical vulnerabilities in Apache Tomcat within SAP Commerce Cloud affecting HY_COM 2205, COM_CLOUD 2211, and COM_CLOUD 2211-JDK21, with a CVSS score of 9.6.
CVE-2025-42928: A deserialization vulnerability in SAP jConnect – SDK for ASE, critically rated with a CVSS score of 9.1.
The vulnerabilities can be exploited remotely, potentially impacting data and service availability. It is crucial for organizations to apply the patches promptly to mitigate these risks.
CVE-2025-42928: A deserialization vulnerability in SAP jConnect – SDK for ASE, critically rated with a CVSS score of 9.1.
Additional High-Severity Vulnerabilities
CVE-2025-42878: Sensitive data exposure in SAP Web Dispatcher and Internet Communication Manager (ICM).
CVE-2025-42877: Memory corruption in SAP Web Dispatcher, ICM, and SAP Content Server.
CVE-2025-42874 & CVE-2025-48976: Denial-of-service vulnerabilities in SAP NetWeaver and SAP Business Objects.
CVE-2025-42876: Missing authorization check in SAP S/4HANA Private Cloud Financials General Ledger.
The update also addresses medium-severity issues, including missing authentication and authorization checks, information disclosure, cross-site scripting (XSS), denial of service in the SAPUI5 Markdown-it component, and server-side request forgery (SSRF) in SAP BusinessObjects BI Platform.
Organizations are advised to follow SAP's security hardening guidelines, review security configurations regularly, and implement monthly patches. Critical and high-severity vulnerabilities should be prioritized, tested, and deployed in production environments as part of a structured patch management process.
For detailed information, visit the SAP Security Notes .
Based on reporting by GBHackers.
