Skip to content

CVE-2025-42957

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
November 11, 2025
Last Seen
December 9, 2025
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

SAP has issued its December security updates, fixing 14 vulnerabilities across various products, including three critical-severity flaws. The most severe, CVE-2025-42880, has a CVSS score of 9.9 and involves a code injection issue in SAP Solution Manager ST 720, allowing authenticated attackers to e...

SAP has released its November security updates, which include 18 new security advisories. Among these, a critical vulnerability in the SQL Anywhere Monitor (CVE-2025-42890) has been identified, receiving a maximum CVSS score of 10 due to hardcoded credentials. Enterprises using SAP systems are urged...

SAP announced a maximum severity security flaw in SQL Anywhere Monitor (Non-GUI), tracked as CVE-2025-42890, which involves hard-coded credentials that could allow arbitrary code execution. The flaw received a CVSS score of 10 and was disclosed as part of SAP's November 2025 Security Patch Day, whic...

Public Exploits

Checking GitHub for proof-of-concept code…