CVE-2025-42937

Published Oct 14, 2025

Last updated 4 months ago

Overview

Description
SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the application.
Source
cna@sap.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cna@sap.com
CWE-35

Social media

Hype score
Not currently trending
  1. Remote Code Execution in SAP-Druckprotokoll: Sicherheitslücke CVE-2025-42937 betrifft tausende Unternehmen - Sicherheitsforscher entdecken Schwachstelle im SAP-Druckprotokoll https://t.co/zDH8hyiwuf #sap #sapsecurity

    @KolaricDav5471

    16 Feb 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-42937 (CVSS:9.8, CRITICAL) is Awaiting Analysis. SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated..https://t.co/PfjmwvCMy4 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    19 Oct 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. **CVE-2025-42937** pertains to the SAP Print Service (SAPSprint), a component responsible for handling printing tasks within SAP environments. The vulnerability arises from insufficient validation of user-supplied path information, enabling an attacker to perform directory

    @CveTodo

    14 Oct 2025

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-42937 SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directo… https://t.co/WFqMEr2QDY

    @CVEnew

    14 Oct 2025

    338 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. [CVE-2025-42937: CRITICAL] SAPSprint vulnerability allows attackers to overwrite system files, compromising data integrity, confidentiality, and system availability. Ensure validation of user-provided path i...#cve,CVE-2025-42937,#cybersecurity https://t.co/LdUApmJsQ6 https://t.c

    @CveFindCom

    14 Oct 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.