Target Industry
Indiscriminate, opportunistic targeting.
Overview
SAP issued a total of 26 security notes as part of its September 2025 Security Patch Day, including four categorised as HotNews due to their critical severity. Among the most significant vulnerabilities are those involving insecure deserialisation in SAP NetWeaver and insecure file operations in SAP NetWeaver AS Java.
Below lists the four HotNews vulnerabilities and four high-priority vulnerabilities addressed:
- Critical Vulnerabilities
- CVE-2025-42944 (CVSS 10.0) – Insecure deserialisation in SAP NetWeaver allows remote code execution
- CVE-2025-42922 (CVSS 9.9) – Insecure file operations in SAP NetWeaver AS Java enable unauthorised access
- CVE-2023-27500 (CVSS 9.6) – Directory traversal in SAP NetWeaver AS ABAP may lead to system compromise
- CVE-2025-42958 (CVSS 9.1) – Missing authentication check in SAP NetWeaver allows privilege escalation
- High-Priority Vulnerabilities
- CVE-2025-42933 (CVSS 8.8) – Insecure storage in SAP Business One could expose sensitive data
- CVE-2025-42929 (CVSS 8.1) – Input validation flaw in SAP LT Replication Server risks data integrity
- CVE-2025-42916 (CVSS 8.1) – Input validation issue in SAP S/4HANA may allow unauthorised actions
- CVE-2025-27428 (CVSS 7.7) – Security misconfiguration in SAP NetWeaver AS ABAP affects system stability
Impact
The vulnerabilities can lead to significant operational disruptions, data breaches, and financial losses. For instance, CVE-2025-42944 allows unauthenticated threat actors to execute arbitrary commands, potentially leading to full system compromise. The financial implications can be severe, with potential costs associated with data recovery, regulatory fines, and reputational damage.
Exploitation
Exploitation of these vulnerabilities can occur through methods such as sending crafted requests to vulnerable endpoints or utilising insecure deserialisation techniques. Threat actors may leverage tools to automate the exploitation process, especially for vulnerabilities with high CVSS scores.
Containment, Mitigations & Remediations
To mitigate these vulnerabilities, SAP recommends applying the latest security patches immediately. Organisations should also implement network segmentation, restrict access to sensitive components, and conduct regular security audits.
Threat Landscape
The threat landscape for SAP systems is evolving, with increasingly sophisticated attack methods. Threat actors are motivated by financial gain, espionage, and disruption of services. The active exploitation of vulnerabilities like CVE-2025-42957 highlights the urgent need for organisations to prioritise security.
Threat Group
Threat groups targeting SAP vulnerabilities often include cybercriminal organisations and state-sponsored actors. These groups utilise sophisticated tactics, including social engineering and automated tools, to exploit vulnerabilities in SAP systems.
Further Information
Intelligence Terminology Yardstick













