External risk intelligence

SAP Print Service Path Traversal Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-42937

SAP Print Service (SAPSprint) is a localized component designed to manage print queues and spooler functions between SAP systems and local or network printers. While it operates over a network, it is typically deployed within internal corporate networks to facilitate printing services and is not intended to be exposed directly to the public internet.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

SAP's Print Service is vulnerable to an attack where unauthorized users could overwrite critical system files by manipulating file paths. This could significantly impact the application's confidentiality, integrity, and availability. The main concern is confirming whether this specific SAP component is relevant and exposed within our environment.

  • Attackers could overwrite system files via file path flaws.
  • Affects SAP Print Service, a critical but localized component.
  • Confirm relevance and exposure to our SAP printing setup.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the SAP Print Service. These requests would leverage improper path validation to access and modify critical system files outside of the intended directory, leading to severe disruptions.

  • No authentication required.
  • Manipulate file paths to overwrite system files.
  • High impact on confidentiality, integrity, and availability.

Live Threat

Current exploitation, exposure, and threat context

SAP Print Service (SAPSprint) could allow an unauthenticated attacker to overwrite system files by manipulating path information. This could impact the confidentiality, integrity, and availability of the application when supported by the advisory.

  • System files could be overwritten.
  • Path traversal via network input.
  • Application disruption and data loss.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in SAP Print Service (SAPSprint) requires immediate attention from the SAP Basis and Infrastructure teams, as it allows unauthenticated attackers to overwrite critical system files. The first step is to identify all instances of SAP Print Service, confirm their network exposure and business criticality, and then establish ownership for remediation planning.

  • SAP Basis and Infrastructure teams own the issue.
  • Verify network exposure and business criticality.
  • Plan remediation during the next maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is SAP Print Service (SAPSprint)?

SAP Print Service, or SAPSprint, is a software component that manages print queues and spooler data. It acts as a bridge, allowing SAP applications to communicate with printers on a local or network level, ensuring that documents generated by business processes are sent to the correct output hardware.

What does path traversal mean in CVE-2025-42937?

This vulnerability, classified as CWE-35 (Path Traversal), occurs when the software does not properly validate file path inputs. Because the service fails to verify these paths, an attacker can manipulate requests to move outside of designated folders, potentially overwriting critical system files and damaging the application's integrity.

How does an attacker trigger this vulnerability?

An unauthenticated user triggers this bug by sending specially crafted network requests to the SAP Print Service that include malicious file path sequences. Simply connecting to the service is insufficient; the attack requires sending these specific, manipulated inputs to trick the service into accessing unintended directories.

Is my SAP Print Service instance at risk?

According to Halo Surface Signal, this component is typically deployed within internal corporate networks to facilitate printing and is not intended to be exposed to the public internet. You should prioritize assets where this service might be inadvertently accessible from outside your secure perimeter, as those are the primary targets.

What should I do first to address this CVE?

Begin by auditing your infrastructure to locate all instances of SAP Print Service. Once identified, verify their network accessibility and determine their importance to your business operations. This information allows your technical teams to prioritize and plan the necessary security updates during your next maintenance window.

References