SAP’s Patch Parade: New Fixes for Java Flaws & File Follies!
SAP released 16 new patches, including fixes for critical vulnerabilities. Particularly, CVE-2025-42944, a deserialization flaw, comes with new protections. Another patch targets CVE-2025-42937, a directory traversal bug. Users should apply these updates pronto, as hungry threat actors are always on the prowl for SAP bugs to nibble on.

Hot Take:
Looks like SAP’s security team has been busier than a cat in a laser pointer factory! With 16 new and updated patches, they’re cranking out fixes faster than you can say “insecure deserialization flaw”. It’s like the cyber equivalent of whack-a-mole, and SAP’s got the mallet!
Key Points:
- SAP released 16 new and updated security patches, including three critical-severity vulnerabilities.
- One critical flaw, CVE-2025-42944, was patched again for additional protection.
- Other critical issues include a directory traversal bug and an unrestricted file upload defect.
- Two high-severity vulnerabilities were also addressed in Commerce Cloud and Data Hub Integration Suite.
- The remaining patches cover medium- and low-severity issues across various SAP products.
Already a member? Log in here