SAP (1)

SAP fixes critical vulnerabilities in NetWeaver application servers

Teilen:

SAP has fixed two critical vulnerabilities affecting NetWeaver web application server that could be exploited to escalate privileges and access restricted information.

As part of the January Security Patch Day, the vendor also released updates for other products to patch 12 additional issues rated with medium and high severity.

“SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape,” reads the company’s security bulletin.

The four most severe security problem SAP addressed this month are summarized as follows:

  • CVE-2025-0070critical severity, 9.9 score): Improper authentication in SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to exploit improper authentication checks, resulting in privilege escalation and significantly impacting confidentiality, integrity, and availability.
  • CVE-2025-0066critical severity, 9.9 score: Information disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) occurs due to weak access controls, enabling an attacker to access restricted information and significantly compromising confidentiality, integrity, and availability.
  • CVE-2025-0063high severity, 8.8 score: SQL injection vulnerability in SAP NetWeaver AS ABAP and ABAP Platform arises from a lack of authorization checks for certain RFC function modules. This allows an attacker with basic privileges to compromise an Informix database, leading to a complete loss of confidentiality, integrity, and availability.
  • CVE-2025-0061high severity, 8.7 score: Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform allow an unauthenticated attacker to perform session hijacking over the network due to an information disclosure issue. This enables the attacker to access and modify all application data.

Impact and recommendations

SAP products serve large enterprises across industries such as manufacturing, finance, retail, healthcare, and government, fulfilling critical roles for managing business operations and customer relations.

SAP NetWeaver is a core platform for running ABAP applications and enabling secure communication via the Internet Communication Framework. It’s typically used by IT administrators, developers, and consultants in enterprises managing ERP systems for finance, HR, and supply chain.

SAP BusinessObjects is a platform for reporting, analytics, and data visualization used by analysts, decision-makers, and IT teams to derive insights and support strategic decisions.

Hackers in the past have targeted SAP products that had not been updated to address known vulnerabilities or were improperly configured, leaving networks exposed to breaches.

The German vendor strongly recommends that customers apply the latest patches available to protect their SAP environment.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:37 am, Juni 6, 2025
Wetter-Symbol 11°C
L: 10° | H: 12°
klarer Himmel
Luftfeuchtigkeit: 88 %
Druck: 1004 mb
Wind: 12 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 9%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:45 am
Sonnenuntergang: 9:12 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
10° | 12°°C 1 mm 100% 14 mph 88 % 1009 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 16°°C 1 mm 100% 14 mph 96 % 1009 mb 0 mm/h
So. Juni 08 10:00 pm
Wetter-Symbol
8° | 16°°C 0 mm 0% 12 mph 88 % 1023 mb 0 mm/h
Mo. Juni 09 10:00 pm
Wetter-Symbol
10° | 20°°C 0 mm 0% 10 mph 89 % 1025 mb 0 mm/h
Di. Juni 10 10:00 pm
Wetter-Symbol
12° | 21°°C 0.6 mm 60% 10 mph 85 % 1023 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 9 mph 88 % 1004 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 9 mph 87 % 1005 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
15° | 17°°C 0 mm 0% 12 mph 72 % 1006 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
20° | 20°°C 1 mm 100% 11 mph 67 % 1008 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
20° | 20°°C 0.29 mm 29% 14 mph 33 % 1008 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 9 mph 46 % 1009 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 4 mph 65 % 1009 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 7 mph 75 % 1008 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€88,796.93
-3.11%
Ethereum(ETH)
€2,110.47
-7.54%
Fesseln(USDT)
€0.87
-0.02%
XRP(XRP)
€1.83
-4.66%
Solana(SOL)
€127.03
-5.33%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.149469
-9.44%
Shiba Inu(SHIB)
€0.000010
-6.44%
Pepe(PEPE)
€0.000010
-10.37%
Peanut das Eichhörnchen(PNUT)
€0.233638
-5.20%
Nach oben scrollen