-
Non-Product Related Assistance
Request for existing cases, user IDs, Portal navigation support and more
SAP Patch Day Bulletin - 2025
SAP Security Patch Day – January 2025
This post shares information on Security Notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 14th of January 2025, SAP Security Patch Day saw the release of 14 new Security Notes.
Note# | Title | Severity | CVSS |
|---|---|---|---|
[CVE-2025-0070] Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform Product- SAP NetWeaver Application Server for ABAP and ABAP Platform, Versions – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 7.97, 8.04, 9.12, 9.13, 9.14 | Critical | ||
[CVE-2025-0066] Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform(Internet Communication Framework) Product- SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework), Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 912, SAP_BASIS 913, SAP_BASIS 914 | Critical | ||
[CVE-2025-0063] SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform Product – SAP NetWeaver AS ABAP and ABAP Platform, Version – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 | High | ||
[CVE-2025-0061] Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform Additional CVE - CVE-2025-0060 Product- SAP BusinessObjects Business Intelligence Platform, Versions – ENTERPRISE 420, 430, 2025 | High | ||
[CVE-2025-0069] DLL Hijacking vulnerability in SAPSetup Product- SAPSetup, Version – LMSAPSETUP 9.0 | High | ||
[CVE-2025-0058] Information Disclosure vulnerability in SAP Business Workflow and SAP Flexible Workflow | Medium | ||
[CVE-2025-0067] Missing Authorization check in SAP NetWeaver Application Server Java Product- SAP NetWeaver Application Server Java, Version – WD-RUNTIME 7.50 | Medium | ||
[CVE-2025-0055] Information Disclosure vulnerability in SAP GUI for Windows Product- SAP GUI for Windows, Versions – BC-FES-GUI 8.0 | Medium | ||
[CVE-2025-0056] Information Disclosure vulnerability in SAP GUI for Java Product- SAP GUI for Java, Versions – BC-FES-JAV 7.80 | Medium | ||
[CVE-2025-0059] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML) Product- SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML), Versions – KRNL64UC 7.53, KERNEL 7.53, 7.54, 7.77, 7.89, 7.93, 9.12, 9.14 | Medium | ||
[CVE-2025-0053] Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform Product- SAP NetWeaver Application Server for ABAP and ABAP Platform, Version – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757 | Medium | ||
[CVE-2025-0057] Cross-Site Scripting vulnerability in SAP NetWeaver AS JAVA (User Admin Application) | Medium | ||
[CVE-2025-0068] Missing Authorization check in Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP | Medium | ||
Multiple Buffer overflow vulnerabilities in SAP BusinessObjects Business Intelligence Platform (Crystal Reports for Enterprise) Related CVEs - CVE-2024-29131, CVE-2024-29133 | Low | 2.2 |
SAP Security Patch Day - February 2025
This post shares the information on Security Notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 11th of February 2025, SAP Security Patch Day saw the release of 19 new Security Notes. Further, there were 2 updates to previously released Security Notes.
Note# | Title | Priority | CVSS |
|---|---|---|---|
Update to Security Note released on February 2024 Patch Day: [CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application) Product- SAP NetWeaver AS Java (User Admin Application), Version – 7.50 | High | ||
[CVE-2025-0064] Improper Authorization in SAP BusinessObjects Business Intelligence platform (Central Management Console) Product- SAP BusinessObjects Business Intelligence platform (Central Management Console), Versions – ENTERPRISE 430, 2025 | High | ||
[CVE-2025-25243] Path traversal vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog) | High | ||
[CVE-2025-24876] Authentication bypass via authorization code injection in SAP Approuter | High | ||
[CVE-2024-38819] Multiple vulnerabilities in SAP Enterprise Project Connection Related CVEs - CVE-2024-38820, CVE-2024-38828 | High | ||
[CVE-2025-24868] Open Redirect Vulnerability in SAP HANA extended application services, advanced model (User Account and Authentication Services) | High | ||
[CVE-2025-24875] SameSite Defense in Depth not applied for some cookies in SAP Commerce Product- SAP Commerce, Versions – HY_COM 2205, COM_CLOUD 2211 | Medium | ||
[CVE-2025-24874] Missing Defense in Depth Against Clickjacking in SAP Commerce (Backoffice) Product – SAP Commerce (Backoffice), Version – HY_COM 2205, COM_CLOUD 2211 | Medium | ||
Update 1 to Security Note 3417627 - [CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application) Product- SAP NetWeaver AS Java (User Admin Application), Version – 7.50 | Medium | ||
[CVE-2025-24867] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform (BI Launchpad) Product- SAP BusinessObjects Platform (BI Launchpad), Version – ENTERPRISE 430, 2025 | Medium | ||
[CVE-2025-24870] Insecure Key & Secret Management vulnerability in SAP GUI for Windows Product- SAP GUI for Windows, Version – BC-FES-GUI 8.00 | Medium | ||
Multiple vulnerabilities in Apache Solr within SAP Commerce Cloud Related CVEs - CVE-2024-45216, CVE-2024-45217 Versions – HY_COM 2205, COM_CLOUD 2211 | Medium | ||
[CVE-2025-0054] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java Product- SAP NetWeaver Application Server Java, Versions – EP-BASIS 7.50, FRAMEWORK-EXT 7.50 | Medium | ||
[CVE-2025-25241] Missing Authorization check in SAP Fiori Apps Reference Library (My Overtime Requests) Product- SAP Fiori Apps Reference Library (My Overtime Requests), Version – GBX01HR5 605 | Medium | ||
[CVE-2025-23187] Missing Authorization Check in SAP NetWeaver and ABAP Platform (SDCCN) Related CVE - CVE-2025-23189 Product- SAP NetWeaver and ABAP Platform (SDCCN), Versions – ST-PI 2008_1_700, ST-PI 2008_1_710, ST-PI 740 | Medium | ||
[CVE-2025-23193] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP Product- SAP NetWeaver Server ABAP, Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 | Medium | ||
Update to Security Note released on April 2023 Patch Day: [CVE-2023-24527] Improper Access Control in SAP NetWeaver AS Java for Deploy Service Product- SAP NetWeaver AS Java for Deploy Service, Version – ENGINEAPI 7.50, SERVERCORE 7.50 | Medium | ||
[CVE-2025-24869] Information Disclosure vulnerability in SAP NetWeaver Application Server Java | Medium | ||
[CVE-2025-24872] Missing Authorization check in SAP ABAP Platform (ABAP Build Framework) | Medium | ||
[CVE-2025-23190] Missing Authorization check in SAP NetWeaver and ABAP platform (ST-PI) | Medium | ||
[CVE-2025-23191] Cache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERP | Low |
SAP Security Patch Day - March 2025
This post shares the information on Security Notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 11th of March 2025, SAP Security Patch Day saw the release of 21 new Security Notes plus 1 Security Note without CVSS because it's just an advisory. Further, there were 3 updates to previously released Security Notes.
Note# | Title | Priority | CVSS |
[CVE-2025-27434] Cross-Site Scripting (XSS) vulnerability in SAP Commerce (Swagger UI) Product- SAP Commerce (Swagger UI), Version – COM_CLOUD 2211 | High | ||
[CVE-2025-26661] Missing Authorization check in SAP NetWeaver (ABAP Class Builder) Product- SAP NetWeaver (ABAP Class Builder), Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 914 | High | ||
[CVE-2024-38286] Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud Related CVE - CVE-2024-52316 | High | ||
Update to Security Note released on February 2025 Patch Day: [CVE-2025-24876] Authentication bypass via authorization code injection in SAP Approuter | High | ||
Update to Security Note released on July 2024 Patch Day: [CVE-2024-39592] Missing Authorization check in SAP PDCE | High | ||
[CVE-2025-26658] Broken Authentication in SAP Business One (Service Layer) | Medium | ||
[CVE-2025-26659] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML) Product- SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML), Versions – KRNL64UC 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.89, KERNEL 7.93, KERNEL 9.14 | Medium | ||
[CVE-2025-25242] Cross-Site Scripting (XSS) in SAP NetWeaver Application Server ABAP Product- SAP NetWeaver Application Server ABAP, Version – SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 914 | Medium | ||
[CVE-2025-25244] Missing Authorization Check in SAP Business Warehouse (Process Chains) Product – SAP Business Warehouse (Process Chains), Version – DW4CORE 100, DW4CORE 200, DW4CORE 300, DW4CORE 400, DW4CORE 914, SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 750 | Medium | ||
[CVE-2025-27431] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java Product- SAP NetWeaver Application Server Java, Version – AJAX-RUNTIME 7.50 | Medium | ||
[CVE-2025-25245] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) Product- SAP BusinessObjects Business Intelligence Platform (Web Intelligence), Version – ENTERPRISE 430, 2025 | Medium | ||
[CVE-2025-23194] Missing Authentication check in SAP NetWeaver Enterprise Portal (OBN component) Product- SAP NetWeaver Enterprise Portal (OBN component), Version – EP-RUNTIME 7.50 | Medium | ||
[CVE-2025-0071] Information Disclosure vulnerability in SAP Web Dispatcher and Internet Communication Manager Product- SAP Web Dispatcher and Internet Communication Manager, Versions – KRNL64UC 7.53, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.89, WEBDISP 7.93, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.89, KERNEL 7.93, KERNEL 9.14 | Medium | ||
[CVE-2025-0062] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) Product- SAP BusinessObjects Business Intelligence Platform, Version – ENTERPRISE 430, 2025, ENTERPRISECLIENTTOOLS 430, 2025 | Medium | ||
[CVE-2025-27433] Broken Access Control vulnerabilities in SAP S/4HANA (Manage Bank Statements) Related CVE - CVE-2025-27436 Product- SAP S/4HANA (Manage Bank Statements), Versions – S4CORE 107, S4CORE 108 | Medium | ||
[CVE-2025-23188] Missing Authorization check in SAP S/4HANA (RBD) Product- SAP S/4HANA (RBD), Versions – S4CORE 102, 103, 104, 105, 106, 107, 108, EA-FINSERV 618, EA-FINSERV 800 | Medium | ||
[CVE-2025-26660] Broken Access Control in SAP Fiori apps (Posting Library) Product- SAP Fiori apps (Posting Library), Version – S4CORE 103, 104, 105, 106, 107, 108 | Medium | ||
[CVE-2025-26656] Missing Authorization check in S/4HANA (Manage Purchasing Info Records) | Medium | ||
Update to Security Note released on August 2024 Patch Day: [CVE-2024-41736] Information Disclosure vulnerability in SAP Permit to Work | Medium | ||
[CVE-2025-23185] Information Disclosure in SAP Business Objects Business Intelligence Platform | Medium | ||
[CVE-2024-38819] Multiple vulnerabilities in Spring Framework within SAP Commerce Cloud and SAP Datahub Related CVE - CVE-2024-38820 | Low | ||
[CVE-2025-27430] Server Side Request Forgery (SSRF) in SAP CRM and SAP S/4 HANA (Interaction Center) | Low | ||
[CVE-2025-26655] Missing Authorization check in SAP JIT(Outbound) | Low | ||
[CVE-2025-27432] Missing Authorization check in SAP Electronic Invoicing for Brazil (eDocument Cockpit) | Low | ||
Open Source Security Advisory: Best Practices for Securing Spring Boot Actuator Endpoints for applications running on BTP | Low | 0.0 |
SAP Security Patch Day - April 2025
This post shares the information on Security Notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 8th of April 2025, SAP Security Patch Day saw the release of 18 new Security Notes. Further, there were 2 updates to previously released Security Notes.
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2025-27429] Code Injection Vulnerability in SAP S/4HANA (Private Cloud) Product - SAP S/4HANA (Private Cloud), Versions - S4CORE 102, 103, 104, 105, 106, 107, 108 | Critical | ||
[CVE-2025-31330] Code Injection Vulnerability in SAP Landscape Transformation (Analysis Platform) Product - SAP Landscape Transformation (Analysis Platform), Versions - DMIS 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731 | Critical | ||
[CVE-2025-30016] Authentication Bypass Vulnerability in SAP Financial Consolidation | Critical | ||
Update to Security Note released on February 2025 Patch Day: [CVE-2025-0064] Improper Authorization in SAP BusinessObjects Business Intelligence platform | High | ||
[CVE-2025-23186] Mixed Dynamic RFC Destination vulnerability through Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP | High | ||
[CVE-2024-56337] Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat within SAP Commerce Cloud | High | ||
[CVE-2025-30014] Directory Traversal vulnerability in SAP Capital Yield Tax Management | High | ||
[CVE-2025-27428] Directory Traversal vulnerability in SAP NetWeaver and ABAP Platform (Service Data Collection) | High | ||
[CVE-2025-26654] Potential information disclosure vulnerability in SAP Commerce Cloud (Public Cloud) Product - SAP Commerce Cloud (Public Cloud), Version - COM_CLOUD 2211 | Medium | ||
[CVE-2025-30013] Code Injection vulnerability in SAP ERP BW Business Content Product - SAP ERP BW Business Content, Versions - BI_CONT 707, 737, 747, 757 | Medium | ||
[CVE-2025-31332] Insecure File permissions vulnerability in SAP BusinessObjects Business Intelligence Platform Product - SAP BusinessObjects Business Intelligence Platform, Version - ENTERPRISE 430 | Medium | ||
[CVE-2025-26657] Information Disclosure vulnerability in SAP KMC WPC Product - SAP KMC WPC, Version - KMC-WPC 7.50 | Medium | ||
[CVE-2025-26653] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML) Product - SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML), Versions - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.14 | Medium | ||
[CVE-2025-30017] Missing Authorization check in SAP Solution Manager Product - SAP Solution Manager, Versions - ST 720, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 914 | Medium | ||
[CVE-2025-31333] Odata meta-data tampering in SAP S4CORE entity Product - SAP S4CORE entity, Versions - S4CORE 107, 108 | Medium | ||
[CVE-2025-27437] Missing Authorization check in SAP NetWeaver Application Server ABAP (Virus Scan Interface) Product - SAP NetWeaver Application Server ABAP (Virus Scan Interface), Versions - SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 | Medium | ||
[CVE-2025-31331] Authorization Bypass vulnerability in SAP NetWeaver Product - SAP NetWeaver, Versions - SAP_ABA 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, 75I | Medium | ||
[CVE-2025-27435] Information Disclosure Vulnerability in SAP Commerce Cloud Product - SAP Commerce Cloud, Versions - HY_COM 2205, COM_CLOUD 2211 | Medium | ||
[CVE-2025-30015] Memory Corruption vulnerability in SAP NetWeaver and ABAP Platform (Application Server ABAP) Product - SAP NetWeaver and ABAP Platform (Application Server ABAP), Versions - KRNL64UC 7.53, KERNEL 7.53, 7.54 | Medium | ||
Update to Security Note released on March 2025 Patch Day: [CVE-2025-27430] Server Side Request Forgery (SSRF) in SAP CRM and SAP S/4 HANA (Interaction Center) | Low |
3 new Security Notes were released after the scheduled Monthly Patch Day. Additionally, 2 previously released Security Notes were updated.
[CVE-2025-31324] Missing Authorization check in SAP NetWeaver (Visual Composer development server) | Critical | ||
Update to Security Note released on April 2025 Patch Day: Product - SAP S/4HANA (Private Cloud), Versions - S4CORE 102, 103, 104, 105, 106, 107, 108 | Critical | ||
Update to Security Note released on April 2025 Patch Day: Product - SAP Landscape Transformation (Analysis Platform), Versions - DMIS 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731 | Critical | ||
[CVE-2025-31328] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4 HANA (Learning Solution) Product- SAP S/4 HANA (Learning Solution), Versions – S4HCMGXX 100, 101 | Medium | ||
[CVE-2025-31327] OData meta-data property entity tampering in SAP Field Logistics | Medium |
SAP Security Patch Day - May 2025
This post shares the information on Security Notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 13th of May 2025, SAP Security Patch Day saw the release of 16 new Security Notes. Further, there were 2 updates to previously released Security Notes.
Note# | Title | Priority | CVSS |
Update to Security Note released on April 2025 Patch Day: [CVE-2025-31324] Missing Authorization check in SAP NetWeaver (Visual Composer development server) | Critical | ||
[CVE-2025-42999] Insecure Deserialization in SAP NetWeaver (Visual Composer development server) Product – SAP NetWeaver (Visual Composer development server) Version – VCFRAMEWORK 7.50 | Critical | ||
[CVE-2025-30018] Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit) Related CVE - CVE-2025-30009, CVE-2025-30010, CVE-2025-30011, CVE-2025-30012 Product – SAP Supplier Relationship Management (Live Auction Cockpit) | High | ||
[CVE-2025-43010] Code injection vulnerability in SAP S/4HANA Cloud Private Edition or On Premise(SCM Master Data Layer (MDL)) Product- SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) Versions – S4CORE 102, 103, 104, 105, 106, 107, 108, SCM_BASIS 700, 701, 702, 712, 713, 714 | High | ||
[CVE-2025-43000] Information Disclosure Vulnerability in SAP Business Objects Business Intelligence Platform (PMW) Product – SAP Business Objects Business Intelligence Platform (PMW) | High | ||
[CVE-2025-43011] Missing Authorization Check in SAP Landscape Transformation (PCL Basis) Product – SAP Landscape Transformation (PCL Basis) | High | ||
Update to Security Note released on July 2024 Patch Day: [CVE-2024-39592] Missing Authorization check in SAP PDCE | High | ||
[CVE-2025-42997] Information Disclosure vulnerability in SAP Gateway Client Product- SAP Gateway Client | Medium | ||
[CVE-2025-43003] Information Disclosure vulnerability in SAP S/4HANA (Private Cloud & On-Premise) | Medium | ||
[CVE-2025-43009] Missing Authorization check in SAP Service Parts Management (SPM) | Medium | ||
[CVE-2025-43007] Missing Authorization check in SAP Service Parts Management (SPM) | Medium | ||
[CVE-2025-31329] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform Versions - SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 | Medium | ||
[CVE-2025-43006] Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog) | Medium | ||
[CVE-2025-43008] Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal | Medium | ||
[CVE-2025-43004] Security Misconfiguration Vulnerability in SAP Digital Manufacturing (Production Operator Dashboard) Version – CTNR-DME-PODFOUNDATION-MS 1.0 | Medium | ||
[CVE-2025-26662] Cross-Site Scripting (XSS) vulnerability in the SAP Data Services Management Console | Medium | ||
[CVE-2025-43002] Missing Authorization check in SAP S4/HANA (OData meta-data property) | Medium | ||
[CVE-2025-43005] Information Disclosure vulnerability in SAP GUI for Windows Product- SAP GUI for Windows | Medium |
|
4 previously released Security Notes were updated after the scheduled Monthly Patch Day.
Update to Security Note released on January 2025 Patch Day: Product – SAP BusinessObjects Business Intelligence Platform | High | ||
Update to Security Note released on May 2025 Patch Day: Product – SAP Landscape Transformation (PCL Basis) | High | ||
Update to Security Note released on May 2025 Patch Day: [CVE-2025-43008] Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal | Medium | ||
Update to Security Note released on February 2025 Patch Day: | Low |
SAP Security Patch Day - June 2025
This post shares the information on Security Notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 10th of June 2025, SAP Security Patch Day saw the release of 14 new Security Notes.
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2025-42989] Missing Authorization check in SAP NetWeaver Application Server for ABAP | Critical | ||
[CVE-2025-42982] Information Disclosure in SAP GRC (AC Plugin) | High | ||
[CVE-2025-42983] Missing Authorization check in SAP Business Warehouse and SAP Plug-In Basis Product – SAP Business Warehouse and SAP Plug-In Basis Versions – PI_BASIS 2006_1_700, 701, 702, 731, 740, SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, 758, 914, 915 | High | ||
[CVE-2025-23192] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence (BI Workspace) | High | ||
[CVE-2025-42977] Directory Traversal vulnerability in SAP NetWeaver Visual Composer | High | ||
[CVE-2025-42994] Multiple vulnerabilities in SAP MDM Server Related CVE - CVE-2025-42995, CVE-2025-42996 | High | ||
[CVE-2025-42993] Missing Authorization Check in SAP S/4HANA (Enterprise Event Enablement) Product – SAP S/4HANA (Enterprise Event Enablement) | Medium | ||
[CVE-2025-31325] Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver (ABAP Keyword Documentation) Product- SAP NetWeaver (ABAP Keyword Documentation) Version – SAP_BASIS 758 | Medium | ||
[CVE-2025-42984] Missing Authorization check in SAP S/4HANA (Manage Central Purchase Contract application) Product – SAP S/4HANA (Manage Central Purchase Contract application) | Medium | ||
[CVE-2025-42998] Security misconfiguration vulnerability in SAP Business One Integration Framework Product – SAP Business One Integration Framework | Medium | ||
[CVE-2025-42987] Missing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statement) | Medium | ||
[CVE-2025-42991] Missing Authorization check in SAP S/4HANA (Bank Account Application) Product- SAP S/4HANA (Bank Account Application) | Medium | ||
[CVE-2025-42988] Server-Side Request Forgery in SAP Business Objects Business Intelligence Platform | Low | ||
[CVE-2025-42990] HTML Injection in Unprotected SAPUI5 applications | Low |
SAP Security Patch Day - July 2025
This post shares information on Security Notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 8th of July 2025, SAP Security Patch Day saw the release of 27 new Security Notes. Further, there were 4 updates to previously released Security Notes.
Note# | Title | Priority | CVSS |
|---|---|---|---|
Update to Security Note released on May 2025 Patch Day: [CVE-2025-30012] Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit) Product – SAP Supplier Relationship Management (Live Auction Cockpit) | Critical | ||
[CVE-2025-42967] Code Injection vulnerability in SAP S/4HANA and SAP SCM (Characteristic Propagation) | Critical | ||
[CVE-2025-42980] Insecure Deserialization in SAP NetWeaver Enterprise Portal Federated Portal Network | Critical | ||
[CVE-2025-42964] Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration Product – SAP NetWeaver Enterprise Portal Administration Version – EP-RUNTIME 7.50 | Critical | ||
[CVE-2025-42966] Insecure Deserialization vulnerability in SAP NetWeaver (XML Data Archiving Service) | Critical | ||
[CVE-2025-42963] Insecure Deserialization in SAP NetWeaver Application Server for Java (Log Viewer ) | Critical | ||
[CVE-2025-42959] Missing Authentication check after implementation of SAP Security Note 3007182 and 3537476 | High | ||
[CVE-2025-42953] Missing Authorization check in SAP NetWeaver Application Server for ABAP Product – SAP NetWeaver Application Server for ABAP | High | ||
[CVE-2024-53677] Insecure File Operations vulnerability in SAP Business Objects Business Intelligence Platform (CMC) Product- SAP Business Objects Business Intelligence Platform (CMC) Version – ENTERPRISE 430, 2025 | High | ||
[CVE-2025-42952] Missing Authorization check in SAP Business Warehouse and SAP Plug-In Basis Product – SAP Business Warehouse and SAP Plug-In Basis | High | ||
Update to Security Note released on June 2025 Patch Day: Product – SAP NetWeaver Visual Composer | High | ||
[CVE-2025-43001] Multiple Privilege Escalation Vulnerabilities in SAPCAR CVEs - CVE-2025-42992 Product – SAPCAR | Medium | ||
Update to Security Note released on June 2025 Patch Day: | Medium | ||
Update to Security Note released on May 2025 Patch Day: | Medium | ||
[CVE-2025-42981] Multiple vulnerabilities in SAP NetWeaver Application Server ABAP CVE - CVE-2025-42956 | Medium | ||
[CVE-2025-42969] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform Product- SAP NetWeaver Application Server ABAP and ABAP Platform | Medium | ||
[CVE-2025-42962] Cross-Site Scripting (XSS) vulnerability in SAP Business Warehouse (Business Explorer Web 3.5 loading animation) | Medium | ||
[CVE-2025-42985] Open Redirect vulnerability in SAP BusinessObjects Content Administrator workbench | Medium | ||
[CVE-2025-42970] Directory Traversal vulnerability in SAPCAR | Medium | ||
[CVE-2025-42979] Insecure Key & Secret Management vulnerability in SAP GUI for Windows Versions - BC-FES-GUI 8.00 | Medium | ||
[CVE-2025-42973] Cross-Site Scripting (XSS) vulnerability in SAP Data Services (DQ Report) | Medium | ||
[CVE-2025-42968] Missing Authorization check in SAP NetWeaver (RFC enabled function module) | Medium | ||
[CVE-2025-42961] Missing Authorization check in SAP NetWeaver Application Server for ABAP | Medium | ||
[CVE-2025-42960] Missing Authorization Check in SAP Business Warehouse and SAP BW/4HANA BEx Tools | Medium | ||
[CVE-2025-42986] Missing Authorization check in SAP NetWeaver and ABAP Platform | Medium | ||
[CVE-2025-42974] Missing Authorization Check in SAP NetWeaver and ABAP Platform (SDCCN) | Medium | ||
[CVE-2025-31326] HTML Injection vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) | Medium | ||
[CVE-2025-42965] Server Side Request Forgery(SSRF) vulnerability in SAP BusinessObjects BI Platform Central Management Console Promotion Management Application | Medium | ||
[CVE-2025-42971] Memory Corruption vulnerability in SAPCAR | Medium | ||
[CVE-2025-42978] Insufficiently Secure Hostname Verification for Outbound TLS Connections in SAP NetWeaver Application Server Java | Low | ||
[CVE-2025-42954] Denial of service (DOS) in SAP NetWeaver Business Warehouse (CCAW application) | Low |
1 new Security Note was released after the scheduled Monthly Patch Day. Additionally, 6 previously released Security Notes were updated.
Update to Security Note released on July 2025 Patch Day: [CVE-2025-42966] Insecure Deserialization vulnerability in SAP NetWeaver (XML Data Archiving Service) | Critical | ||
Update to Security Note released on July 2025 Patch Day: [CVE-2025-42959] Missing Authentication check after implementation of SAP Security Note 3007182 and 3537476 | High | ||
Update to Security Note released on July 2025 Patch Day: [CVE-2025-42981] Multiple vulnerabilities in SAP NetWeaver Application Server ABAP CVE - CVE-2025-42956 | Medium | ||
Update to Security Note released on July 2025 Patch Day: [CVE-2025-42969] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform Product- SAP NetWeaver Application Server ABAP and ABAP Platform | Medium | ||
Update to Security Note released on May 2025 Patch Day: [CVE-2025-43008] Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal | Medium | ||
[CVE-2025-42947] Code Injection vulnerability in SAP FICA ODN framework | Medium |
| |
Update to Security Note released on July 2025 Patch Day: [CVE-2025-42978] Insufficiently Secure Hostname Verification for Outbound TLS Connections in SAP NetWeaver Application Server Java | Low |
SAP Security Patch Day - August 2025
This post shares the information on Security Notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 12th of August 2025, SAP Security Patch Day saw the release of 15 new Security Notes. Further, there were 4 updates to previously released Security Notes.
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2025-42957] Code Injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise) Product - SAP S/4HANA (Private Cloud or On-Premise) | Critical | ||
[CVE-2025-42950] Code Injection Vulnerability in SAP Landscape Transformation (Analysis Platform) Product - SAP Landscape Transformation (Analysis Platform) | Critical | ||
Update to Security Note released on April 2025 Patch Day: [CVE-2025-27429] Code Injection Vulnerability in SAP S/4HANA (Private Cloud or On-Premise) Product – SAP S/4HANA (Private Cloud or On-Premise) | Critical | ||
[CVE-2025-42951] Broken Authorization in SAP Business One (SLD) Product - SAP Business One (SLD) | High | ||
[CVE-2025-42976] Multiple vulnerabilities in SAP NetWeaver Application Server ABAP (BIC Document) Additional CVE - CVE-2025-42975 Product - SAP NetWeaver Application Server ABAP (BIC Document) | High | ||
[CVE-2025-42946] Directory Traversal vulnerability in SAP S/4HANA (Bank Communication Management) Product - SAP S/4HANA (Bank Communication Management) | Medium | ||
[CVE-2025-42945] HTML Injection vulnerability in SAP NetWeaver Application Server ABAP Product - SAP NetWeaver Application Server ABAP | Medium | ||
[CVE-2025-42942] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP Product - SAP NetWeaver Application Server for ABAP | Medium | ||
[CVE-2025-42948] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform Product - SAP NetWeaver ABAP Platform | Medium | ||
Update to Security Note released on January 2025 Patch Day: [CVE-2025-0059] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML) | Medium | ||
[CVE-2025-42936] Missing Authorization check in SAP NetWeaver Application Server for ABAP Product - SAP NetWeaver Application Server for ABAP | Medium | ||
Update to Security Note released on March 2025 Patch Day: [CVE-2025-23194] Missing Authentication check in SAP NetWeaver Enterprise Portal (OBN component) | Medium | ||
[CVE-2025-42949] Missing Authorization check in ABAP Platform Product - ABAP Platform | Medium | ||
[CVE-2025-42943] Information Disclosure in SAP GUI for Windows Product - SAP GUI for Windows | Medium | ||
[CVE-2025-42934] CRLF Injection vulnerability in SAP S/4HANA (Supplier invoice) Product - SAP S/4HANA (Supplier invoice) | Medium | ||
Update to Security Note released on April 2025 Patch Day: [CVE-2025-31331] Authorization Bypass vulnerability in SAP NetWeaver Product – SAP NetWeaver | Medium | ||
[CVE-2025-42935] Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform(Internet Communication Manager) Product - SAP NetWeaver AS for ABAP and ABAP Platform(Internet Communication Manager) | Medium | ||
[CVE-2025-42955] Missing authorization check in SAP Cloud Connector Product - SAP Cloud Connector | Low | ||
[CVE-2025-42941] Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad) Product - SAP Fiori (Launchpad) | Low |
SAP Security Patch Day - September 2025
This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 9th of September 2025, SAP Security Patch Day saw the release of 21 new security notes. Further, there were 5 updates to previously released security notes.
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2025-42944] Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4) Product - SAP Netweaver AS Java | Critical | ||
[CVE-2025-42922] Insecure File Operations vulnerability in SAP NetWeaver AS Java (Deploy Web Service) Product - SAP NetWeaver AS Java (Deploy Web Service) | Critical | ||
Update to Security Note released on March 2023 Patch Day: [CVE-2023-27500] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform Product – SAP NetWeaver AS for ABAP and ABAP Platform | Critical | ||
[CVE-2025-42958] Missing Authentication check in SAP NetWeaver Product - SAP NetWeaver | Critical | ||
[CVE-2025-42933] Insecure Storage of Sensitive Information in SAP Business One (SLD) Product - SAP Business One (SLD) | High | ||
[CVE-2025-42929] Missing input validation vulnerability in SAP Landscape Transformation Replication Server Product - SAP Landscape Transformation Replication Server | High | ||
[CVE-2025-42916] Missing input validation vulnerability in SAP S/4HANA (Private Cloud or On-Premise) Product - SAP S/4HANA (Private Cloud or On-Premise) | High | ||
Update to Security Note released on April 2025 Patch Day: [CVE-2025-27428] Directory Traversal vulnerability in SAP NetWeaver and ABAP Platform (Service Data Collection) | High | ||
[CVE-2025-22228] Security Misconfiguration vulnerability in Spring security within SAP Commerce Cloud and SAP Datahub Product - SAP Commerce Cloud and SAP Datahub | Medium | ||
[CVE-2025-42930] Denial of Service (DoS) vulnerability in SAP Business Planning and Consolidation Product - SAP Business Planning and Consolidation | Medium | ||
[CVE-2025-42912] Missing Authorization check in SAP HCM (My Timesheet Fiori 2.0 application) Additional CVEs - CVE-2025-42913, CVE-2025-42914 Product - SAP HCM (My Timesheet Fiori 2.0 application) | Medium | ||
[CVE-2025-42917] Missing Authorization check in SAP HCM (Approve Timesheets Fiori 2.0 application) Product - SAP HCM (Approve Timesheets Fiori 2.0 application) | Medium | ||
[CVE-2023-5072] Denial of Service (DoS) vulnerability due to outdated JSON library used in SAP BusinessObjects Business Intelligence Platform Product - SAP BusinessObjects Business Intelligence Platform | Medium | ||
[CVE-2025-42920] Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship Management Product - SAP Supplier Relationship Management | Medium | ||
[CVE-2025-42938] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform Product - SAP NetWeaver ABAP Platform | Medium | ||
[CVE-2025-42915] Missing Authorization Check in Fiori app (Manage Payment Blocks) Product - Fiori app (Manage Payment Blocks) | Medium | ||
[CVE-2025-42926] Missing Authentication check in SAP NetWeaver Application Server Java Product - SAP NetWeaver Application Server Java | Medium | ||
[CVE-2025-42911] Missing Authorization check in SAP NetWeaver (Service Data Download) Product - SAP NetWeaver (Service Data Download) | Medium | ||
Update to Security Note released on July 2025 Patch Day: [CVE-2025-42961] Missing Authorization check in SAP NetWeaver Application Server for ABAP Product - SAP NetWeaver Application Server for ABAP | Medium | ||
[CVE-2025-42925] Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service) Product - SAP NetWeaver AS Java (IIOP Service) | Medium | ||
[CVE-2025-42923] Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App (F4044 Manage Work Center Groups) Product - SAP Fiori App (F4044 Manage Work Center Groups) | Medium | ||
[CVE-2025-42918] Missing Authorization check in SAP NetWeaver Application Server for ABAP (Background Processing) Product - SAP NetWeaver Application Server for ABAP (Background Processing) | Medium | ||
Update to Security Note released on April 2025 Patch Day: [CVE-2025-31331] Authorization Bypass vulnerability in SAP NetWeaver Product - SAP NetWeaver | Medium |
| |
Update to Security Note released on August 2025 Patch Day: [CVE-2025-42941] Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad) Product - SAP Fiori (Launchpad) | Low |
| |
[CVE-2025-42927] Information Disclosure due to Outdated OpenSSL Version in SAP NetWeaver AS Java (Adobe Document Service) Product - SAP NetWeaver AS Java (Adobe Document Service) | Low | ||
|
| [CVE-2024-13009] Potential Improper Resource Release vulnerability in SAP Commerce Cloud Product - SAP Commerce Cloud | Low |
1 new security note was released after the scheduled Monthly Patch Day. Additionally, 7 previously released security notes were updated.
Update to Security Note released on September 2025 Patch Day: [CVE-2025-42944] Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4) Product - SAP Netweaver (RMI-P4) Version - SERVERCORE 7.50 | Critical | ||
Update to Security Note released on September 2025 Patch Day: [CVE-2025-42922] Insecure File Operations vulnerability in SAP NetWeaver AS Java (Deploy Web Service) Product - SAP NetWeaver AS Java (Deploy Web Service) Version - J2EE-APPS 7.50 | Critical | ||
Update to Security Note released on March 2023 Patch Day: [CVE-2023-27500] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform Product – SAP NetWeaver AS for ABAP and ABAP Platform Version – 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757 | Critical | ||
Update to Security Note released on September 2025 Patch Day: [CVE-2025-42917] Missing Authorization check in SAP HCM (Approve Timesheets Fiori 2.0 application) Product - SAP HCM (Approve Timesheets Fiori 2.0 application) Version - GBX01HR5 605 | Medium | ||
Update to Security Note released on September 2025 Patch Day: [CVE-2025-42912] Missing Authorization check in SAP HCM (My Timesheet Fiori 2.0 application) Product - SAP HCM (My Timesheet Fiori 2.0 application) Version - GBX01HR5 605 | Medium | ||
Update to Security Note released on September 2025 Patch Day: [CVE-2025-42915] Missing Authorization Check in Fiori app (Manage Payment Blocks) Product - Fiori app (Manage Payment Blocks) Version - S4CORE 107, 108 | Medium | ||
Update to Security Note released on September 2025 Patch Day: [CVE-2025-42918] Missing Authorization check in SAP NetWeaver Application Server for ABAP (Background Processing) Product - SAP NetWeaver Application Server for ABAP (Background Processing) Version - SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816 | Medium | ||
[CVE-2025-42907] Server-Side Request Forgery in SAP BI Platform Product - SAP BI Platform Version - ENTERPRISE 430, 2025, 2027 | Medium |
SAP Security Patch Day - October 2025
This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 14th of October 2025, SAP security patch day saw the release of 13 new security notes. Further, there were 4 updates to previously released security notes.
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2025-42944] Security Hardening for Insecure Deserialization in SAP NetWeaver AS Java | Critical | ||
Update to Security Note released on September 2025 Patch Day: [CVE-2025-42944] Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4) | Critical | ||
[CVE-2025-42937] Directory Traversal vulnerability in SAP Print Service | Critical | ||
[CVE-2025-42910] Unrestricted File Upload Vulnerability in SAP Supplier Relationship Management | Critical | ||
[CVE-2025-5115] Denial of service (DOS) in SAP Commerce Cloud (Search and Navigation) | High | ||
[CVE-2025-48913] Security Misconfiguration vulnerability in SAP Data Hub Integration Suite | High | ||
Update to Security Note released on January 2025 Patch Day: [CVE-2025-0059] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML) | Medium | ||
[CVE-2025-42901] Code Injection vulnerability in SAP Application Server for ABAP (BAPI Browser) | Medium | ||
[CVE-2025-42908] Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP | Medium | ||
Update to Security Note released on June 2025 Patch Day: [CVE-2025-42984] Missing Authorization check in SAP S/4HANA (Manage Central Purchase Contract application) | Medium | ||
[CVE-2025-42906] Directory Traversal vulnerability in SAP Commerce Cloud | Medium | ||
[CVE-2025-42902] Memory Corruption vulnerability in SAP Netweaver AS ABAP and ABAP Platform | Medium | ||
[CVE-2025-42939] Missing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statements) | Medium | ||
Update to Security Note released on April 2025 Patch Day: [CVE-2025-31331] Authorization Bypass vulnerability in SAP NetWeaver | Medium | ||
[CVE-2025-42903] User Enumeration and Sensitive Data Exposure via RFC Function in SAP Financial Service Claims Management Product - SAP Financial Service Claims Management | Medium | ||
[CVE-2025-31672] Deserialization Vulnerability in SAP BusinessObjects (Web Intelligence and Platform Search) | Low | ||
[CVE-2025-42909] Security Misconfiguration vulnerability in SAP Cloud Appliance Library Appliances Product - SAP Cloud Appliance Library Appliances | Low |
6 previously released security notes were updated after the scheduled monthly Patch Day.
Update to Security Note released on October 2025 Patch Day: [CVE-2025-42944] Security Hardening for Insecure Deserialization in SAP NetWeaver AS Java | Critical | ||
Update to Security Note released on October 2025 Patch Day: [CVE-2025-42910] Unrestricted File Upload Vulnerability in SAP Supplier Relationship Management | Critical | ||
Update to Security Note released on October 2025 Patch Day: [CVE-2025-5115] Denial of service (DOS) in SAP Commerce Cloud (Search and Navigation) | High | ||
Update to Security Note released on August 2025 Patch Day: [CVE-2025-42942] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP | Medium | ||
Update to Security Note released on September 2025 Patch Day: [CVE-2025-42911] Missing Authorization check in SAP NetWeaver (Service Data Download) | Medium | ||
Update to Security Note released on October 2025 Patch Day: [CVE-2025-31672] Deserialization Vulnerability in SAP | Low |
SAP Security Patch Day - November 2025
This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 11th of November 2025, SAP security patch day saw the release of 18 new security notes. Further, there were 2 updates to previously released security notes.
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2025-42890] Insecure key & Secret Management vulnerability in SQL Anywhere Monitor (Non-Gui) | Critical | ||
Update to Security Note released on October 2025 Patch Day: [CVE-2025-42944] Security Hardening for Insecure Deserialization in SAP NetWeaver AS Java | Critical | ||
[CVE-2025-42887] Code Injection vulnerability in SAP Solution Manager | Critical | ||
[CVE-2025-42940] Memory Corruption vulnerability in SAP CommonCryptoLib | High | ||
[CVE-2025-42895] Code Injection vulnerability in SAP HANA JDBC Client | Medium | ||
[CVE-2025-42892] OS Command Injection vulnerability in SAP Business Connector | Medium | ||
[CVE-2025-42894] Path Traversal vulnerability in SAP Business Connector | Medium | ||
[CVE-2025-42884] JNDI Injection vulnerability in SAP NetWeaver Enterprise Portal | Medium | ||
[CVE-2025-42924] Open Redirect vulnerabilities in SAP S/4HANA landscape (SAP E-Recruiting BSP) | Medium | ||
[CVE-2025-42893] Open Redirect vulnerability in SAP Business Connector | Medium | ||
[CVE-2025-42886] Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector | Medium | ||
[CVE-2025-42885] Missing authentication in SAP HANA 2.0 (hdbrss) | Medium | ||
[CVE-2025-42888] Information Disclosure vulnerability in SAP GUI for Windows | Medium | ||
[CVE-2025-42889] SQL Injection vulnerability in SAP Starter Solution (PL SAFT) | Medium | ||
[CVE-2025-42919] Information Disclosure vulnerability in SAP NetWeaver Application Server Java | Medium | ||
[CVE-2025-42897] Information Disclosure vulnerability in SAP Business One (SLD) | Medium | ||
[CVE-2025-42899] Missing Authorization check in SAP S4CORE (Manage Journal Entries) | Medium | ||
[CVE-2025-42882] Missing Authorization check in SAP NetWeaver Application Server for ABAP | Medium | ||
| 3426825 | Update to Security Note released on February 2025 Patch Day: [CVE-2025-23191] Cache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERP | Low | 3.1 |
[CVE-2025-42883] Insecure File Operations vulnerability in SAP NetWeaver Application Server for ABAP (Migration Workbench) | Low |
3 previously released security notes were updated after the scheduled monthly patch day.
Note# | Title | Priority | CVSS |
|---|---|---|---|
Update to Security Note released on November 2025 Patch Day: [CVE-2025-42887] Code Injection vulnerability in SAP Solution Manager | Critical | ||
| Update to Security Note released on July 2025 Patch Day: [CVE-2025-42961] Missing Authorization check in SAP NetWeaver Application Server for ABAP Product - SAP NetWeaver Application Server for ABAP Version(s) – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816 | Medium | ||
Update to Security Note released on July 2025 Patch Day: [CVE-2025-42986] Missing Authorization check in SAP NetWeaver and ABAP Platform Product - SAP NetWeaver and ABAP Platform | Medium |
SAP Security Patch Day - December 2025
This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 9th of December 2025, SAP security patch day saw the release of 14 new security notes.
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2025-42880] Code Injection vulnerability in SAP Solution Manager | Critical | ||
[CVE-2025-55754] Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud | Critical | ||
[CVE-2025-42928] Deserialization Vulnerability in SAP jConnect - SDK for ASE | Critical | ||
[CVE-2025-42878] Sensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM) | High | ||
[CVE-2025-42874] Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius) | High | ||
[CVE-2025-48976] Denial of service (DOS) in SAP Business Objects | High | ||
[CVE-2025-42877] Memory Corruption vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | High | ||
[CVE-2025-42876] Missing Authorization Check in SAP S/4 HANA Private Cloud (Financials General Ledger) | High | ||
[CVE-2025-42875] Missing Authentication check in SAP NetWeaver Internet Communication Framework | Medium | ||
[CVE-2025-42904] Information Disclosure vulnerability in Application Server ABAP | Medium | ||
[CVE-2025-42872] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal | Medium | ||
[CVE-2025-42873] Denial of Service (DoS) in SAPUI5 framework (Markdown-it component) | Medium | ||
[CVE-2025-42891] Missing Authorization check in SAP Enterprise Search for ABAP | Medium | ||
[CVE-2025-42896] Server-Side Request Forgery (SSRF) in SAP BusinessObjects Business Intelligence Platform | Medium |
2 previously released security notes were updated after the scheduled monthly patch day.
Update to Security Note released on December 2025 Patch Day: [CVE-2025-55754] Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud | Critical | ||
Update to Security Note released on December 2025 Patch Day: [CVE-2025-42928] Deserialization Vulnerability in SAP jConnect - SDK for ASE | Critical |
To know more about the security researchers and research companies who have contributed for security patches of this month, visit here.
SAP is committed to delivering trustworthy products and cloud services. Secure configuration is essential to ensuring secure operation and data integrity. We have therefore documented security recommendations that are consolidated in this document to help you configure the best security for your SAP portfolio.
Archived blogs from previous years are available here.
If you have any comments or feedback about this post, you can write to secure@sap.com.