CVE-2025-42937
Description
SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the application.
Summary dbcve.org
SAP Print Service (SAPSprint) contains a path traversal vulnerability due to insufficient validation of user-supplied path information. An unauthenticated attacker can use directory traversal sequences (e.g., ../../) to escape the intended directory and overwrite arbitrary system files on the host, achieving full compromise of confidentiality, integrity, and availability.
Mitigation
Apply the SAP security patch for CVE-2025-42937 immediately. As an interim measure, restrict network access to SAPSprint ports and implement web application firewall rules to block path traversal patterns.