Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2025121601120808 | Publication Time | 2025/12/16 13:17 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2025/12/16 13:17 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】SAP Releases a Critical Security Advisory for Two of Its Products (CVE-2025-42928) (CVE-2025-42880) |
|||
|
[Content] 【CVE-2025-42880, CVSS: 9.9】Due to a lack of input filtering mechanisms, SAP Solution Manager allows authenticated attackers to inject malicious code when invoking support remote-enabled function modules, which may affect the confidentiality, integrity, and availability of the system. |
|||
|
[Affected Platform] 【CVE-2025-42880】SAP Solution Manager ST version 720 |
|||
|
[Recommended Actions] https://support.sap.com/en/my-support/knowledge-base/security-notes-news/december-2025.html |
|||
| [Reference] |
|||