CVE-2025-42937: SAP SE SAP Print Service
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the application.
Affected products
- SAP SE SAP Print Service: version 8.10 only
Published 2025-10-14. Last modified 2026-10-08.