SAP fixes severe safety points – here is how you can keep protected



  • CVE-2025-42887 in SAP Answer Supervisor permits unauthenticated code injection and full system takeover
  • Vulnerability scored 9.9/10; patch launched in SAP’s November 2025 replace
  • SAP additionally fastened CVE-2024-42890, a ten/10 flaw in SQL Anyplace Monitor

SAP Answer Supervisor, an software lifecycle administration (ALM) platform with tens of 1000’s of person organizations, carried a essential severity vulnerability that allowed menace actors to totally take over compromised endpoints, specialists have warned.

Safety researchers SecurityBridge, who notified SAP after discovering the flaw, described as a “lacking enter sanitation” vulnerability, which permits unauthenticated menace actors to insert malicious code when calling a remote-enabled operate module.



0
Show Comments (0) Hide Comments (0)
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
0
Would love your thoughts, please comment.x
()
x