SAP セキュリティパッチデー 2025 年 5 月

このページでは、SAP 製品で発見された脆弱性を改善するセキュリティノートに関する情報を共有しています。SAP は、Support Portal にアクセスし SAP ランドスケープを保護するために優先的にパッチを適用することを強くお奨めします。

2025 年 5 月 13 日に、SAP セキュリティパッチデーに 16 の新しいセキュリティノートがリリースされました。さらに、以前にリリースされたセキュリティノートに対する 2 つの更新がありました。

Note#

Title

Priority

CVSS

3594142

Update to Security Note released on April 2025 Patch Day:

[CVE-2025-31324Missing Authorization check in SAP NetWeaver (Visual Composer development server)
Product – SAP NetWeaver (Visual Composer development server)
Version – VCFRAMEWORK 7.50

Critical

10.0

3604119

[CVE-2025-42999Insecure Deserialization in SAP NetWeaver (Visual Composer development server)

Product – SAP NetWeaver (Visual Composer development server)

Version – VCFRAMEWORK 7.50

Critical 

9.1

3578900

[CVE-2025-30018Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)

Related CVE - CVE-2025-30009CVE-2025-30010CVE-2025-30011CVE-2025-30012

Product – SAP Supplier Relationship Management (Live Auction Cockpit)
Version – SRM_SERVER 7.14

High

8.6

3600859

[CVE-2025-43010Code injection vulnerability in SAP S/4HANA Cloud Private Edition or On Premise(SCM Master Data Layer (MDL))

Product- SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL))

Versions – S4CORE 102, 103, 104, 105, 106, 107, 108, SCM_BASIS 700, 701, 702, 712, 713, 714

High

8.3

3586013

[CVE-2025-43000Information Disclosure Vulnerability in SAP Business Objects Business Intelligence Platform (PMW)

Product – SAP Business Objects Business Intelligence Platform (PMW)
Versions – ENTERPRISE 430, 2025, 2027

High

7.9

3591978

[CVE-2025-43011Missing Authorization Check in SAP Landscape Transformation (PCL Basis)

Product – SAP Landscape Transformation (PCL Basis)
Versions – DMIS 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2018_1_752, 2020, S4CORE 102, 103, 104, 105, 106, 107, 108

High

7.7

3483344

Update to Security Note released on July 2024 Patch Day:

[CVE-2024-39592Missing Authorization check in SAP PDCE
Product – SAP PDCE
Versions – S4CORE 102, 103, S4COREOP 104, 105, 106, 107, 108

High

7.7

3577300

[CVE-2025-42997Information Disclosure vulnerability in SAP Gateway Client

Product- SAP Gateway Client
Versions – SAP_GWFND 752, 753, 754, 755, 756, 757, 758

Medium

6.6

3596033

[CVE-2025-43003Information Disclosure vulnerability in SAP S/4HANA (Private Cloud & On-Premise)
Product - SAP S/4HANA (Private Cloud & On-Premise)
Versions - S4CRM 204, 205, 206, S4CEXT 107, 108, BBPCRM 702, 712, 713, 714

Medium

6.4

2491817

[CVE-2025-43009Missing Authorization check in SAP Service Parts Management (SPM)
Product -  SAP Service Parts Management (SPM)
Versions - SAP_APPL 600, 602, 603, 604, 605, 606, 616, 617, 618, SAPSCORE 111, S4CORE 100, 101, 102

Medium

6.3

2719724

[CVE-2025-43007Missing Authorization check in SAP Service Parts Management (SPM)
Product - SAP Service Parts Management (SPM)
Versions - SAP_APPL 617, 618, SAPSCORE 116, S4CORE 100, 101, 102, 103

Medium

6.3

3577287

[CVE-2025-31329Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Product - SAP NetWeaver Application Server ABAP and ABAP Platform

Versions - SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758

Medium

6.2

3588455

[CVE-2025-43006Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog)
Product – SAP Supplier Relationship Management (Master Data Management Catalog)
Version – SRM_MDM_CAT 7.52

Medium

6.1

3585992

[CVE-2025-43008Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal
Product – SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal
Versions – S4HCMCPT 100, 101, SAP_HRCPT 600, 604, 608

Medium

5.8

3571096

[CVE-2025-43004Security Misconfiguration Vulnerability in SAP Digital Manufacturing (Production Operator Dashboard)
Product - SAP Digital Manufacturing (Production Operator Dashboard)

Version – CTNR-DME-PODFOUNDATION-MS 1.0

Medium

5.3

3558755

[CVE-2025-26662Cross-Site Scripting (XSS) vulnerability in the SAP Data Services Management Console
Product – SAP Data Services Management Console
Version – SBOP DS JOB SERVER 4.3

Medium

4.4

3227940

[CVE-2025-43002Missing Authorization check in SAP S4/HANA (OData meta-data property)
Product - SAP S4/HANA (OData meta-data property)
Versions - S4CORE 102, 103, 104, 105, 106

Medium

4.3

3574520

[CVE-2025-43005Information Disclosure vulnerability in SAP GUI for Windows

Product- SAP GUI for Windows
Version – BC-FES-GUI 8.00

Medium

4.3



月次で計画されているパッチデー後に、新たに 4 つのセキュリティノートがリリースされました。

3474398

Update to Security Note released on January 2025 Patch Day:
[CVE-2025-0061] Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform
Additional CVE - CVE-2025-0060

Product – SAP BusinessObjects Business Intelligence Platform
Versions – ENTERPRISE 420, 430, 2025

High

8.7

3591978

Update to Security Note released on May 2025 Patch Day:
[CVE-2025-43011] Missing Authorization Check in SAP Landscape Transformation (PCL Basis)

Product – SAP Landscape Transformation (PCL Basis)
Versions – DMIS 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2018_1_752, 2020, S4CORE 102, 103, 104, 105, 106, 107, 108

High

7.7

3585992

Update to Security Note released on May 2025 Patch Day:

[CVE-2025-43008] Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal
Product – SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal
Versions – S4HCMCPT 100, 101, SAP_HRCPT 600, 604, 608

Medium

5.8

3426825

Update to Security Note released on February 2025 Patch Day:
[CVE-2025-23191] Cache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERP
Product – SAP Fiori for SAP ERP
Versions – SAP_GWFND 740, 750, 751, 752, 753, 754, 755, 756, 757, 758

Low

3.1

今月のセキュリティパッチを提供してきたセキュリティ研究者や調査会社の詳細については、こちらをご覧ください。

SAP  は、信頼できる製品とクラウドサービスの提供に尽力しています。安全な運用とデータの完全性を確保するには、安全な設定が不可欠です。そのため、SAP ポートフォリオに最適なセキュリティを設定できるように、この文書に統合されたセキュリティ推奨事項が文書化されています。

過去のアーカイブブログは、こちらからご覧いただけます。

このページに関するコメントまたはフィードバックがある場合は secure@sap.com 宛にご連絡ください。(お問い合わせは英語でお願いいたします。)