Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

Stablecoins will remodel funds within the World South

October 16, 2025

An alarming variety of satellite tv for pc communications usually are not encrypted

October 16, 2025

Sharjah Police Improve Desert Safety Forward of Winter Tourism Season

October 16, 2025
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • Stablecoins will remodel funds within the World South
  • An alarming variety of satellite tv for pc communications usually are not encrypted
  • Sharjah Police Improve Desert Safety Forward of Winter Tourism Season
  • “You’ll be able to’t hustle eternally,” – Olumide Okubadejo
  • Inside Well being appoints Sylvia Weir as CEO
  • 5 Key Security Suggestions from NPCI for Safe Digital Funds throughout Festive Season
  • How can founders in Africa construct startups that truly scale?
  • Revolve Renewable Energy is a inventory to look at, this analyst says
Thursday, October 16
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - New SAP NetWeaver Bug Lets Attackers Take Over Servers With out Login
Cybersecurity & Digital Rights

New SAP NetWeaver Bug Lets Attackers Take Over Servers With out Login

NextTechBy NextTechOctober 15, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
New SAP NetWeaver Bug Lets Attackers Take Over Servers With out Login
Share
Facebook Twitter LinkedIn Pinterest Email


Oct 15, 2025Ravie Lakshmanan Enterprise Software program / Vulnerability

SAP has rolled out safety fixes for 13 new safety points, together with further hardening for a maximum-severity bug in SAP NetWeaver AS Java that might lead to arbitrary command execution.

The vulnerability, tracked as CVE-2025-42944, carries a CVSS rating of 10.0. It has been described as a case of insecure deserialization.

“As a consequence of a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker may exploit the system by the RMI-P4 module by submitting a malicious payload to an open port,” in response to an outline of the flag in CVE.org.

DFIR Retainer Services

“The deserialization of such untrusted Java objects may result in arbitrary OS command execution, posing a excessive affect to the appliance’s confidentiality, integrity, and availability.”

Whereas the vulnerability was first addressed by SAP final month, safety firm Onapsis mentioned the newest repair supplies additional safeguards to safe towards the chance posed by deserialization.

“The extra layer of safety is predicated on implementing a JVM-wide filter (jdk.serialFilter) that forestalls devoted courses from being deserialized,” it famous. “The listing of really helpful courses and packages to dam was outlined in collaboration with the ORL and is split into a compulsory part and an elective part.”

One other important vulnerability of notice is CVE-2025-42937 (CVSS rating: 9.8), a listing traversal flaw in SAP Print Service that arises on account of inadequate path validation, permitting an unauthenticated attacker to succeed in the guardian listing and overwrite system recordsdata.

The third important flaw patched by SAP considerations an unrestricted file add bug in SAP Provider Relationship Administration (CVE-2025-42910, CVSS rating: 9.0) that might allow an attacker to add arbitrary recordsdata, together with malicious executables that might affect the confidentiality, integrity, and availability of the appliance.

CIS Build Kits

Whereas there isn’t any proof of those flaws being exploited within the wild, it is important that customers apply the newest patches and mitigations as quickly as attainable to keep away from potential threats.

“Deserialization stays the foremost threat,” Pathlock’s Jonathan Stross mentioned. “The P4/RMI chain continues to drive important publicity in AS Java, with SAP issuing each a direct repair and a hardened JVM configuration to cut back gadget‑class abuse.”

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the newest breakthroughs, get unique updates, and join with a world community of future-focused thinkers.
Unlock tomorrow’s developments right this moment: learn extra, subscribe to our e-newsletter, and turn out to be a part of the NextTech neighborhood at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

F5 Breach Exposes BIG-IP Supply Code — Nation-State Hackers Behind Large Intrusion

October 15, 2025

The AI hype practice, house knowledge facilities, and lifelike robotic heads • Graham Cluley

October 14, 2025

How you can watch De Ridder vs Hernandez

October 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Economy News

Stablecoins will remodel funds within the World South

By NextTechOctober 16, 2025

Stablecoins—digital currencies which can be tethered to real-world fiat currencies—won’t solely unlock cheaper transaction prices…

An alarming variety of satellite tv for pc communications usually are not encrypted

October 16, 2025

Sharjah Police Improve Desert Safety Forward of Winter Tourism Season

October 16, 2025
Top Trending

Stablecoins will remodel funds within the World South

By NextTechOctober 16, 2025

Stablecoins—digital currencies which can be tethered to real-world fiat currencies—won’t solely unlock…

An alarming variety of satellite tv for pc communications usually are not encrypted

By NextTechOctober 16, 2025

A bunch of college researchers within the U.S. have spent the final…

Sharjah Police Improve Desert Safety Forward of Winter Tourism Season

By NextTechOctober 16, 2025

Because the winter tourism season approaches, Sharjah Police have intensified their safety…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!