CVE-2025-42937Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the application.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-35

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-16: 1Technical Details · 2026-02-16: 102-16
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Online-Magazin für IT-Sicherheit@KolaricDav5471
    Disclosure

    Remote Code Execution in SAP-Druckprotokoll: Sicherheitslücke CVE-2025-42937 betrifft tausende Unternehmen - Sicherheitsforscher entdecken Schwachstelle im SAP-Druckprotokoll https://www.all-about-security.de/remote-code-execution-in-sap-druckprotokoll-sicherheitsluecke-cve-2025-42937-betrifft-tausende-unternehmen/ #sap #sapsecurity

    Post summary

    The article announces the discovery of a remote code execution vulnerability (CVE‑2025‑42937) in SAP's print protocol, but does not provide exploit details, patches, or evidence of active exploitation.

    0000034
    18 followersView on X

Explore more