Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

Is Father’s Day getting more respect? Depends on who you ask

June 15, 2025

Spaniards sour on tourism industry amid housing crunch

June 15, 2025

David Beckham, Gary Oldman and others honored by King Charles III

June 14, 2025
Facebook X (Twitter) Instagram
Trending
  • Is Father’s Day getting more respect? Depends on who you ask
  • Spaniards sour on tourism industry amid housing crunch
  • David Beckham, Gary Oldman and others honored by King Charles III
  • Pope Leo XIV’s fashion choices draw excitement and scrutiny
  • TikTok star Khaby Lame plays soccer in Brazil after US detention
  • Tips for getting along when college grads move back home
  • The Paris Games flame rises again — but it’s no longer ‘Olympic’
  • Pitbull’s fans party like clones, bald caps included
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Sunday, June 15
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » SAP Patches High-Severity Vulnerabilities in Commerce, NetWeaver
Cybersecurity

SAP Patches High-Severity Vulnerabilities in Commerce, NetWeaver

adminBy adminMarch 11, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 48


Enterprise software maker SAP on Tuesday announced the release of 21 new and three updated security notes on its March 2025 security patch day.

The company included five high-priority security notes in its advisory, namely three new notes that address vulnerabilities in Commerce, NetWeaver, and Commerce Cloud, and two updated notes that resolve flaws in Approuter and PDCE.

The most severe of these issues are CVE-2025-27434 and CVE-2025-26661 (CVSS score of 8.8), described as a cross-site scripting (XSS) bug in Commerce and a missing authorization check in NetWeaver.

The XSS issue resides in the open source library Swagger UI, and could allow an unauthenticated attacker to inject malicious code if they convince a user “to place a malicious payload into an input field”, application security firm Onapsis notes.

The NetWeaver vulnerability was discovered in the transaction SA38, and allows access to restricted functionality.

SAP also released patches for Commerce Cloud to resolve two high-severity bugs in Apache Tomcat that could be exploited to cause a denial-of-service (DoS) condition or bypass authentication.

The updated high-priority security notes resolve an authentication bypass in Approuter and a missing authorization check in PDCE. The notes were initially published in February 2025 and July 2024.

On Tuesday, SAP also announced the release of 15 medium-priority security notes that resolve flaws in Business One, NetWeaver, Business Warehouse, BusinessObjects, Web Dispatcher and Internet Communication Manager, S/4HANA, Fiori apps, and Permit to Work.

Advertisement. Scroll to continue reading.

SAP also released five low-priority notes this week, including a note with a CVSS score of 0.0, which “provides best practice information about custom Java applications in SAP BTP implemented with the Spring Framework,” as Onapsis explains.

The note provides details on the endpoints that the debugging and monitoring tool Spring Boot Activator may expose, and which could introduce serious vulnerabilities is not properly secured.

Related: SAP Releases 21 Security Patches

Related: SAP Patches Critical Vulnerabilities in NetWeaver

Related: SAP Patches Critical Vulnerability in NetWeaver

Related: SAP Patches High-Severity Vulnerability in Web Dispatcher



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

O2 Service Vulnerability Exposed User Location

May 20, 2025

Madhu Gottumukkala Officially Announced as CISA Deputy Director

May 20, 2025

BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software

May 19, 2025

Printer Company Procolored Served Infected Software for Months

May 19, 2025

UK Legal Aid Agency Finds Data Breach Following Cyberattack

May 19, 2025

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

May 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
Billionaires

Private Equity’s First Woman Billionaire Owns San Diego Soccer Team

June 11, 2025

Lauren Leichtman spent four decades building a super successful private equity firm with her husband.…

Billionaire Walmart Heiress Urges People To ‘Mobilize’ At June 14 Anti-Trump Protests

June 11, 2025

Anduril Cofounder Trae Stephens Is Now A Billionaire

June 10, 2025

The Unlikely Group Getting Rich Off Dave’s Hot Chicken’s $1 Billion Deal

June 9, 2025
Our Picks

Is Father’s Day getting more respect? Depends on who you ask

June 15, 2025

Spaniards sour on tourism industry amid housing crunch

June 15, 2025

David Beckham, Gary Oldman and others honored by King Charles III

June 14, 2025

Pope Leo XIV’s fashion choices draw excitement and scrutiny

June 13, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

After Klarna, Zoom’s CEO also uses an AI avatar on quarterly call

May 23, 2025

Anthropic CEO claims AI models hallucinate less than humans

May 22, 2025

Anthropic’s latest flagship AI sure seems to love using the ‘cyclone’ emoji

May 22, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.