{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Daily Security Review","title":"SAP’s July 2025 Patch Day: Critical Flaws, CVE-2025-30012, and Ransomware Risk","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/eceb262a\"></iframe>","width":"100%","height":180,"duration":3721,"description":"In this episode, we break down SAP’s July 2025 Security Patch Day—a high-stakes moment for any enterprise relying on SAP’s core business applications. With 27 new and 4 updated security notes released, including seven rated as critical, this patch cycle directly targets some of the most serious vulnerabilities seen in SAP environments in recent memory.\nAt the center of this month’s update is CVE-2025-30012, a critical unauthenticated command execution flaw in SAP Supplier Relationship Management (SRM). Initially classified as high priority, this vulnerability has now been escalated to critical status due to its severe impact. Also in the spotlight: a remote code execution bug in SAP S/4HANA and SCM (CVE-2025-42967), and four insecure deserialization vulnerabilities affecting SAP NetWeaver Java systems—longtime targets for threat actors and ransomware groups alike.\nWhile there are no confirmed in-the-wild exploits for these new issues, history tells us that such gaps don’t remain unexploited for long. Just earlier this year, vulnerabilities in SAP’s Visual Composer framework were actively exploited by ransomware operators like BianLian and RansomEXX. As threat actors grow more sophisticated and supply chain targets grow more lucrative, patch speed has never been more important.\nThis episode covers:\nThe vulnerabilities patched in SAP’s July advisory and their real-world risk\nWhy CVSS scoring matters—and how SAP determines what counts as \"critical\"\nThe SAP vulnerability lifecycle, and how organizations can use structured frameworks for patch and incident management\nKey lessons from past exploits, including zero-day activity targeting SAP systems\nThe shared security model in cloud deployments like RISE with SAP—and what you’re responsible for vs. what SAP handles\nWhy alert fatigue and delayed patching are existential threats in SAP environments\nHow to verify your patch level, interpret SAP Notes, and ensure you’re protected\nWe also discuss how critical tools like...","thumbnail_url":"https://img.transistorcdn.com/pL79_MJFeJHamQ_ztImsGmDSMdl27VMk_30TAkieujE/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNzg5/ZjlhNzM5Y2M4Njli/NjkxNzgyODA2Nzhi/MDI2ZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}