SAP has released security updates for 13 new security issues, including a patch for a maximum severity flaw in SAP NetWeaver AS Java that could lead to arbitrary command execution.
See also: SAP: Patch Day notes – Fixing critical vulnerabilities

The vulnerability, tracked as CVE-2025-42944, has a CVSS score of 10.0 and is described as an unsafe deserialization case. An unauthenticated attacker could exploit the system via the RMI-P4 module by submitting a malicious payload to an open port. Deserialization of such untrusted Java objects could lead to arbitrary execution of operating system commands, posing a high risk to the confidentiality, integrity, and availability of the application.
Although the vulnerability was initially patched by SAP last month, security firm Onapsis noted that the latest patch provides additional protection against the risk posed by deserialization. The additional layer of protection is based on the implementation of a JVM-wide filter (jdk.serialFilter) that prevents deserialization of specific classes. The list of recommended classes and packages to block was defined in collaboration with ORL and is divided into a mandatory and an optional section.
See also: Hackers deploy Linux Auto-Color via SAP NetWeaver flaw

Another critical vulnerability worth noting is CVE-2025-42937 (CVSS score: 9.8), a directory traversal vulnerability in SAP Print Service resulting from insufficient path validation, allowing an unauthenticated attacker to reach the parent directory and overwrite system files.
The third critical flaw fixed by SAP concerns an unconstrained file upload flaw in SAP Supplier Relationship Management (CVE-2025-42910, CVSS score: 9.0) that could allow an attacker to upload arbitrary files, including malicious executables that could affect the confidentiality, integrity, and availability of the application.
See also: SAP fixes critical remote code execution flaws

While there is no evidence that these vulnerabilities have been exploited in the wild, it is essential that users apply the latest updates and mitigations as soon as possible to avoid potential risks. Deserialization remains a significant risk, with the P4/RMI continuing to cause critical exposure in AS Java, prompting SAP to issue both an immediate fix and enhanced JVM configuration to mitigate gadget class abuse.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
