menu
techminis

A naukri.com initiative

google-web-stories
source image

Securityaffairs

3d

read

153

img
dot

Image Credit: Securityaffairs

SAP June 2025 Security Patch Day fixed critical NetWeaver bug

  • SAP released a security patch in June 2025 to fix a critical vulnerability in the NetWeaver framework that allowed attackers to bypass authorization checks and escalate privileges.
  • The vulnerability, tracked as CVE-2025-42989 with a CVSS score of 9.6, could impact the integrity and availability of the application by letting authenticated attackers escalate privileges.
  • The flaw was found in SAP's Remote Function Call (RFC) framework, enabling attackers to bypass checks and escalate privileges, posing risks to app integrity and availability.
  • In addition to the critical NetWeaver bug, the June 2025 Security Patch addressed a total of five high-severity flaws and several other medium to low-severity vulnerabilities.

Read Full Article

like

9 Likes

For uninterrupted reading, download the app