Vulnerabilities

SAP patches three critical flaws in December 2025 Security Update

0

SAP has rolled out its December security updates, addressing 14 vulnerabilities across multiple products, including three rated critical.

The most severe issue is CVE-2025-42880 (CVSS 9.9), a code injection flaw in SAP Solution Manager ST 720.
Due to missing input sanitization, an authenticated attacker could inject malicious code via a remote-enabled function module, potentially gaining full control of the system and compromising confidentiality, integrity, and availability.

SAP Solution Manager is widely used for system monitoring, configuration, incident handling, documentation, and test management, making the flaw particularly impactful.

The second critical issue affects SAP Commerce Cloud components in versions HY_COM 2205, COM_CLOUD 2211, and COM_CLOUD 2211-JDK21.
Multiple Apache Tomcat vulnerabilities are grouped under CVE-2025-55754 (CVSS 9.6), posing significant risks to large-scale e-commerce deployments.

SAP Commerce Cloud supports major online retailers with catalog management, pricing, promotions, checkout, order handling, customer account systems, and ERP/CRM integrations.

The third critical flaw, CVE-2025-42928 (CVSS 9.1), is a deserialization vulnerability in SAP jConnect.
Under specific conditions, a high-privileged user could leverage specially crafted input to execute remote code on the target system.

SAP jConnect is a JDBC driver used to connect Java applications with SAP ASE and SAP SQL Anywhere databases.

Beyond the critical issues, SAP’s December bulletin includes fixes for five high-severity and six medium-severity vulnerabilities, covering memory corruption, missing authentication and authorization checks, XSS, and information disclosure.

SAP products remain frequent targets due to their deep integration into enterprise environments and management of sensitive, high-value operations. Earlier this year, researchers observed active exploitation of another code injection flaw (CVE-2025-42957) affecting S/4HANA, Business One, and NetWeaver.

While SAP reports no active exploitation of the 14 newly patched flaws, administrators are strongly advised to apply the updates promptly.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

GhostFrame: The Stealth Phishing Kit hitting millions

Previous article

New Chrome malware targets ChatGPT and DeepSeek Chats

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *