
Exploitation of SAP vulnerability CVE-2017-12637 – Putting things in perspective
On March 19, 2025, CISA added SAP vulnerability CVE-2017-12637 to its Known Exploited Vulnerabilities Catalog, warning of active exploitation. The risk is considered low but significant for customers with specific SAP setups—namely, those using outdated SAP CPS Job Scheduler (version 8) in Java-based environments. The vulnerability allows for the retrieval of sensitive files, potentially compromising the system. SAP advises upgrading to BPA 9.0 or disabling the affected application. Immediate action is recommended for those still using the outdated version.