SAP Addresses Serious Security Issues – Here’s How to Stay Secure


  • CVE-2025-42887 in SAP Solution Manager allows unauthorized code injection and full system takeover
  • Vulnerability scored 9.9/10; patch released in SAP November 2025 update
  • SAP also fixed CVE-2024-42890, a 10/10 flaw in SQL Anywhere Monitor

SAP Solution Manager, an application lifecycle management (ALM) platform with tens of thousands of user organizations, carried a critical severity vulnerability that allowed threat actors to fully take over compromised endpoints, experts have warned.

Security researchers SecurityBridge, which notified SAP after discovering the flaw, described as a “missing input sanitization” vulnerability, which allows unauthorized threat actors to inject malicious code when calling a remotely activated function module.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top