• News/
  • https://www.bleepingcomputer.com/news/security/sap-fixes-critical-vulnerabilities-in-netweaver-application-servers/

SAP fixes critical vulnerabilities in NetWeaver application servers

BleepingComputer
·
Bill Toulas
·
Published Jan 15, 2025
·
Updated

SAP has fixed two critical vulnerabilities affecting NetWeaver web application server that could be exploited to escalate privileges and access restricted information. As part of the January Security Patch Day, the vendor also released updates for other products to patch 12 additional issues rated with medium and high severity. “SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape,” reads the company's security bulletin. The four most severe security problem SAP addressed this month are summarized as follows: SAP products serve large enterprises across industries such as manufacturing, finance, retail, healthcare, and government, fulfilling critical roles for managing business operations and customer relations. SAP NetWeaver is a core platform for running ABAP applications and enabling secure communication via the Internet Communication Framework. It’s typically used by IT administrators, developers, and consultants in enterprises managing ERP systems for finance, HR, and supply chain. SAP BusinessObjects is a platform for reporting, analytics, and data visualization used by analysts, decision-makers, and IT teams to derive insights and support strategic decisions. Hackers in the past have targeted SAP products that had not been updated to address known vulnerabilities or were improperly configured, leaving networks exposed to breaches. The German vendor strongly recommends that customers apply the...

Read full article

Affected Software

3 affected components
SAP NetWeaver
SAP BusinessObjects
SAP NetWeaver web application server
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities have been fixed in this article?

The article discusses two critical vulnerabilities in the SAP NetWeaver application servers that could lead to privilege escalation and unauthorized information access.

2

What is the impact of the vulnerabilities mentioned?

The vulnerabilities could potentially allow attackers to escalate privileges and gain access to restricted information within affected systems.

3

Which SAP products are affected by these vulnerabilities?

The vulnerabilities affect SAP NetWeaver, SAP BusinessObjects, and specifically the SAP NetWeaver web application server.

4

When were the security patches released?

The security patches for these vulnerabilities were released as part of the January Security Patch Day.

5

What is the main focus of the security update?

The main focus of the security update is to address critical vulnerabilities that could be exploited in SAP NetWeaver applications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203