SAP has rolled out its December security updates, addressing 14 vulnerabilities across multiple products, including three rated critical.
The most severe issue is CVE-2025-42880 (CVSS 9.9), a code injection flaw in SAP Solution Manager ST 720.
Due to missing input sanitization, an authenticated attacker could inject malicious code via a remote-enabled function module, potentially gaining full control of the system and compromising confidentiality, integrity, and availability.
SAP Solution Manager is widely used for system monitoring, configuration, incident handling, documentation, and test management, making the flaw particularly impactful.
The second critical issue affects SAP Commerce Cloud components in versions HY_COM 2205, COM_CLOUD 2211, and COM_CLOUD 2211-JDK21.
Multiple Apache Tomcat vulnerabilities are grouped under CVE-2025-55754 (CVSS 9.6), posing significant risks to large-scale e-commerce deployments.
SAP Commerce Cloud supports major online retailers with catalog management, pricing, promotions, checkout, order handling, customer account systems, and ERP/CRM integrations.
The third critical flaw, CVE-2025-42928 (CVSS 9.1), is a deserialization vulnerability in SAP jConnect.
Under specific conditions, a high-privileged user could leverage specially crafted input to execute remote code on the target system.
SAP jConnect is a JDBC driver used to connect Java applications with SAP ASE and SAP SQL Anywhere databases.
Beyond the critical issues, SAP’s December bulletin includes fixes for five high-severity and six medium-severity vulnerabilities, covering memory corruption, missing authentication and authorization checks, XSS, and information disclosure.
SAP products remain frequent targets due to their deep integration into enterprise environments and management of sensitive, high-value operations. Earlier this year, researchers observed active exploitation of another code injection flaw (CVE-2025-42957) affecting S/4HANA, Business One, and NetWeaver.
While SAP reports no active exploitation of the 14 newly patched flaws, administrators are strongly advised to apply the updates promptly.

















Comments