SAP Solves Serious Security Problems: Here’s How to Stay Safe


  • CVE-2025-42887 in SAP Solution Manager allows unauthenticated code injection and full system takeover
  • Vulnerability scored 9.9/10; fix released in SAP November 2025 update
  • SAP also fixed CVE-2024-42890, a 10/10 flaw in SQL Anywhere Monitor

SAP Solution Manager, an application lifecycle management (ALM) platform with tens of thousands of user organizations, contained a critical severity vulnerability that allowed malicious actors to take full control of compromised endpoints, experts warned.

Security researchers SecurityBridge, who informed SAP after discovering the flaw, described it as a “missing input check” vulnerability, which allows unauthenticated threat actors to insert malicious code when calling a remotely activated function module.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top