SAP セキュリティパッチデー 2025 年 3 月
このページでは、SAP 製品で発見された脆弱性を改善するセキュリティノートに関する情報を共有しています。SAP は、Support Portal にアクセスし SAP ランドスケープを保護するために優先的にパッチを適用することを強くお奨めします。
2025 年 3 月 11 日に、SAP セキュリティパッチデーに 21 の新しいセキュリティノートがリリースされました。また、CVSSスコアが付与されていない1件のセキュリティノートもリリースされましたが、これは単なる参考情報です。さらに、以前にリリースされたセキュリティノートに対する 3 つの更新がありました。
Note# | Title | Priority | CVSS |
[CVE-2025-27434] Cross-Site Scripting (XSS) vulnerability in SAP Commerce (Swagger UI) Product- SAP Commerce (Swagger UI), Version – COM_CLOUD 2211 | High | ||
[CVE-2025-26661] Missing Authorization check in SAP NetWeaver (ABAP Class Builder) Product- SAP NetWeaver (ABAP Class Builder), Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 914 | High | ||
[CVE-2024-38286] Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud Related CVE - CVE-2024-52316 | High | ||
Update to Security Note released on February 2025 Patch Day: [CVE-2025-24876] Authentication bypass via authorization code injection in SAP Approuter | High | ||
Update to Security Note released on July 2024 Patch Day: [CVE-2024-39592] Missing Authorization check in SAP PDCE | High | ||
[CVE-2025-26658] Broken Authentication in SAP Business One (Service Layer) | Medium | ||
[CVE-2025-26659] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML) Product- SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML), Versions – KRNL64UC 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.89, KERNEL 7.93, KERNEL 9.14 | Medium | ||
[CVE-2025-25242] Cross-Site Scripting (XSS) in SAP NetWeaver Application Server ABAP Product- SAP NetWeaver Application Server ABAP, Version – SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 914 | Medium | ||
[CVE-2025-25244] Missing Authorization Check in SAP Business Warehouse (Process Chains) Product – SAP Business Warehouse (Process Chains), Version – DW4CORE 100, DW4CORE 200, DW4CORE 300, DW4CORE 400, DW4CORE 914, SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 750 | Medium | ||
[CVE-2025-27431] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java Product- SAP NetWeaver Application Server Java, Version – AJAX-RUNTIME 7.50 | Medium | ||
[CVE-2025-25245] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) Product- SAP BusinessObjects Business Intelligence Platform (Web Intelligence), Version – ENTERPRISE 430, 2025 | Medium | ||
[CVE-2025-23194] Missing Authentication check in SAP NetWeaver Enterprise Portal (OBN component) Product- SAP NetWeaver Enterprise Portal (OBN component), Version – EP-RUNTIME 7.50 | Medium | ||
[CVE-2025-0071] Information Disclosure vulnerability in SAP Web Dispatcher and Internet Communication Manager Product- SAP Web Dispatcher and Internet Communication Manager, Versions – KRNL64UC 7.53, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.89, WEBDISP 7.93, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.89, KERNEL 7.93, KERNEL 9.14 | Medium | ||
[CVE-2025-0062] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) Product- SAP BusinessObjects Business Intelligence Platform, Version – ENTERPRISE 430, 2025, ENTERPRISECLIENTTOOLS 430, 2025 | Medium | ||
[CVE-2025-27433] Broken Access Control vulnerabilities in SAP S/4HANA (Manage Bank Statements) Related CVE - CVE-2025-27436 Product- SAP S/4HANA (Manage Bank Statements), Versions – S4CORE 107, S4CORE 108 | Medium | ||
[CVE-2025-23188] Missing Authorization check in SAP S/4HANA (RBD) Product- SAP S/4HANA (RBD), Versions – S4CORE 102, 103, 104, 105, 106, 107, 108, EA-FINSERV 618, EA-FINSERV 800 | Medium | ||
[CVE-2025-26660] Broken Access Control in SAP Fiori apps (Posting Library) Product- SAP Fiori apps (Posting Library), Version – S4CORE 103, 104, 105, 106, 107, 108 | Medium | ||
[CVE-2025-26656] Missing Authorization check in S/4HANA (Manage Purchasing Info Records) | Medium | ||
Update to Security Note released on August 2024 Patch Day: [CVE-2024-41736] Information Disclosure vulnerability in SAP Permit to Work | Medium | ||
[CVE-2025-23185] Information Disclosure in SAP Business Objects Business Intelligence Platform | Medium | ||
[CVE-2024-38819] Multiple vulnerabilities in Spring Framework within SAP Commerce Cloud and SAP Datahub Related CVE - CVE-2024-38820 | Low | ||
[CVE-2025-27430] Server Side Request Forgery (SSRF) in SAP CRM and SAP S/4 HANA (Interaction Center) | Low | ||
[CVE-2025-26655] Missing Authorization check in SAP JIT(Outbound) | Low | ||
[CVE-2025-27432] Missing Authorization check in SAP Electronic Invoicing for Brazil (eDocument Cockpit) | Low | ||
Open Source Security Advisory: Best Practices for Securing Spring Boot Actuator Endpoints for applications running on BTP | Low | 0.0 |
今月のセキュリティパッチを提供してきたセキュリティ研究者や調査会社の詳細については、こちらをご覧ください。
SAP は、信頼できる製品とクラウドサービスの提供に尽力しています。安全な運用とデータの完全性を確保するには、安全な設定が不可欠です。そのため、SAP ポートフォリオに最適なセキュリティを設定できるように、この文書に統合されたセキュリティ推奨事項が文書化されています。
過去のアーカイブブログは、こちらからご覧いただけます。
このページに関するコメントまたはフィードバックがある場合は secure@sap.com 宛にご連絡ください。(お問い合わせは英語でお願いいたします。)