Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functionalities. This results in a high impact on the confidentiality, integrity, and availability of the application.
https://www.theregister.com/2025/09/10/microsoft_patch_tuesday/
https://www.securityweek.com/sap-patches-critical-netweaver-vulnerabilities/
https://thehackernews.com/2025/09/sap-patches-critical-netweaver-cvss-up.html
https://securityaffairs.com/182040/security/sap-september-2025-patch-day-fixed-4-critical-flaws.html