Skip to content

Key Insights Blog

Read the latest insights from our experts on Cybersecurity and Risk management for SAP. 
SAP Vulnerability

Exploitation of SAP vulnerability CVE-2017-12637 – Putting things in perspective 

On March 19, 2025, CISA added SAP vulnerability CVE-2017-12637 to its Known Exploited Vulnerabilities Catalog, warning of active exploitation. The risk is considered low but significant for customers with specific SAP setups—namely, those using outdated SAP CPS Job Scheduler (version 8) in Java-based environments. The vulnerability allows for the retrieval of sensitive files, potentially compromising the system. SAP advises upgrading to BPA 9.0 or disabling the affected application. Immediate action is recommended for those still using the outdated version.

Read More »