
[CIAD-2025-0051] Multiple vulnerabilities in SAP Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple vulnerabilities in SAP Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: High
Software Affected
SAP Solution Manager
SAP Commerce Cloud
SAP jConnect – SDK for ASE
SAP Web Dispatcher & Internet Communication Manager (ICM)Version
SAP NetWeaver
SAP Business Objects
SAP Web Dispatcher, Internet Communication Manager & SAP Content Server
SAP S/4 HANA Private Cloud (Financials General Ledger)
SAP NetWeaver Internet Communication Framework
Application Server ABAP
SAP NetWeaver Enterprise Portal
SAPUI5 framework (Markdown-it component)
SAP Enterprise Search for ABAP
SAP BusinessObjects Business Intelligence Platform
Overview
Multiple vulnerabilities have been reported, which could be exploited by an attacker to disclose sensitive information, gain elevated privileges, execute arbitrary code, denial-of-service condition, perform Cross-Site Scripting (XSS) and Server-Side Request Forgery (SSRF) on the targeted system.
Target Audience:
SAP system administrators, SAP security teams, IT infrastructure teams managing SAP landscape and Application developers using affected SAP.
Risk Assessment:
Potential for system compromise, data exposure, unauthorized access, privilege abuse, service disruption, arbitrary file upload.
Impact Assessment:
High risk of data breach, execution of arbitrary code, full system compromise, unavailability, security control bypass, and operational disruption.
Description
Multiple vulnerabilities have been reported in SAP products.
Solution
Apply appropriate updates as mentioned by the vendor:
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/december-2025.html
Vendor Information
SAP
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/december-2025.html
References
SAP
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/december-2025.html
CVE Name
CVE-2025-55754
CVE-2025-42928
CVE-2025-42878
CVE-2025-42874
CVE-2025-48976
CVE-2025-42877
CVE-2025-42876
CVE-2025-42875
CVE-2025-42880
CVE-2025-42904
CVE-2025-42872
CVE-2025-42873
CVE-2025-42891
CVE-2025-42896
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmk8IaIACgkQ3jCgcSdc
ys8wIxAAphIw+v6/S7PcGMhZJFutMRPbOnzHvOk14+rbdd9qIyoD8bap4E/AVYXi
U+q/0E5w/SuC6wJvSKfkSSeDoaBsHyaySGJ2Yst9MMRi+Lzi4nPnLOVjI/tk3jHW
fq41oQHFCtbiSuZEbdsHcBfF8JvJ92OA8RNgjKxD/unTvcyseRMWBxaKSmxsDbx6
TJcuJJiC/d+ay+jD+E84fZisEmWktzZ0NWHTxf36I1hQklvEdV79fcqnFh9LdGqO
WTAOHCc89JGz1Z0cX2gM1lfysGG3GWzXdmS2iLyK2VQvgmJzC3dpZoKTdd4oIJON
ng4wZ7XJG2O2qWMkre0JciKt/Nz9zhV1+LvxaKPwz5ST/bwBi02yMx76LL2WYMQS
nO0JYLwDbAuflpXzDXANJDOtjpbee7avjd9WMHnMU/QZNu0g70/glKgKHXKO3WlV
xqOOiBRN2wAu7WBaxR/jqiHvzCEYJjAMJPBC0x3vb7LQPUciiz8m4FK+HlAkiJbK
rSetqjeJY/AMgY8uVDH7zdYpUq1yI/OI+SqvBjJiqVQOOO6gAb9NlsZQ34Fd3txT
Av3HDwVfgQPj0+WUKRa81FWbXPpmTzVotzaIR6vynpx9YfEM6yrYvpfdBc5fOXLV
tUsUustUv+VaDJFb960YD/4TIbS+n5yId3ZIOxnh+5DpdcXH4+I=
=ap2I
—–END PGP SIGNATURE—–


