SAP セキュリティパッチデー 2025 年 9 月
このページでは、SAP 製品で発見された脆弱性を改善するセキュリティノートに関する情報を共有しています。SAP は、Support Portal にアクセスし SAP ランドスケープを保護するために優先的にパッチを適用することを強くお奨めします。
2025 年 9 月 9 日に、SAP セキュリティパッチデーに 21 の新しいセキュリティノートがリリースされました。さらに、以前にリリースされたセキュリティノートに対する 5 つの更新がありました。
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2025-42944] Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4) Product - SAP Netweaver AS Java | Critical | ||
[CVE-2025-42922] Insecure File Operations vulnerability in SAP NetWeaver AS Java (Deploy Web Service) Product - SAP NetWeaver AS Java (Deploy Web Service) | Critical | ||
Update to Security Note released on March 2023 Patch Day: [CVE-2023-27500] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform Product – SAP NetWeaver AS for ABAP and ABAP Platform | Critical | ||
[CVE-2025-42958] Missing Authentication check in SAP NetWeaver Product - SAP NetWeaver | Critical | ||
[CVE-2025-42933] Insecure Storage of Sensitive Information in SAP Business One (SLD) Product - SAP Business One (SLD) | High | ||
[CVE-2025-42929] Missing input validation vulnerability in SAP Landscape Transformation Replication Server Product - SAP Landscape Transformation Replication Server | High | ||
[CVE-2025-42916] Missing input validation vulnerability in SAP S/4HANA (Private Cloud or On-Premise) Product - SAP S/4HANA (Private Cloud or On-Premise) | High | ||
Update to Security Note released on April 2025 Patch Day: [CVE-2025-27428] Directory Traversal vulnerability in SAP NetWeaver and ABAP Platform (Service Data Collection) | High | ||
[CVE-2025-22228] Security Misconfiguration vulnerability in Spring security within SAP Commerce Cloud and SAP Datahub Product - SAP Commerce Cloud and SAP Datahub | Medium | ||
[CVE-2025-42930] Denial of Service (DoS) vulnerability in SAP Business Planning and Consolidation Product - SAP Business Planning and Consolidation | Medium | ||
[CVE-2025-42912] Missing Authorization check in SAP HCM (My Timesheet Fiori 2.0 application) Additional CVEs - CVE-2025-42913, CVE-2025-42914 Product - SAP HCM (My Timesheet Fiori 2.0 application) | Medium | ||
[CVE-2025-42917] Missing Authorization check in SAP HCM (Approve Timesheets Fiori 2.0 application) Product - SAP HCM (Approve Timesheets Fiori 2.0 application) | Medium | ||
[CVE-2023-5072] Denial of Service (DoS) vulnerability due to outdated JSON library used in SAP BusinessObjects Business Intelligence Platform Product - SAP BusinessObjects Business Intelligence Platform | Medium | ||
[CVE-2025-42920] Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship Management Product - SAP Supplier Relationship Management | Medium | ||
[CVE-2025-42938] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform Product - SAP NetWeaver ABAP Platform | Medium | ||
[CVE-2025-42915] Missing Authorization Check in Fiori app (Manage Payment Blocks) Product - Fiori app (Manage Payment Blocks) | Medium | ||
[CVE-2025-42926] Missing Authentication check in SAP NetWeaver Application Server Java Product - SAP NetWeaver Application Server Java | Medium | ||
[CVE-2025-42911] Missing Authorization check in SAP NetWeaver (Service Data Download) Product - SAP NetWeaver (Service Data Download) | Medium | ||
Update to Security Note released on July 2025 Patch Day: [CVE-2025-42961] Missing Authorization check in SAP NetWeaver Application Server for ABAP Product - SAP NetWeaver Application Server for ABAP | Medium | ||
[CVE-2025-42925] Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service) Product - SAP NetWeaver AS Java (IIOP Service) | Medium | ||
[CVE-2025-42923] Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App (F4044 Manage Work Center Groups) Product - SAP Fiori App (F4044 Manage Work Center Groups) | Medium | ||
[CVE-2025-42918] Missing Authorization check in SAP NetWeaver Application Server for ABAP (Background Processing) Product - SAP NetWeaver Application Server for ABAP (Background Processing) | Medium | ||
Update to Security Note released on April 2025 Patch Day: [CVE-2025-31331] Authorization Bypass vulnerability in SAP NetWeaver Product - SAP NetWeaver | Medium |
| |
Update to Security Note released on August 2025 Patch Day: [CVE-2025-42941] Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad) Product - SAP Fiori (Launchpad) | Low |
| |
[CVE-2025-42927] Information Disclosure due to Outdated OpenSSL Version in SAP NetWeaver AS Java (Adobe Document Service) Product - SAP NetWeaver AS Java (Adobe Document Service) | Low | ||
|
| [CVE-2024-13009] Potential Improper Resource Release vulnerability in SAP Commerce Cloud Product - SAP Commerce Cloud | Low |
月次で計画されているパッチデー後に、新たに 1 つのセキュリティノートがリリースされました。さらに、以前にリリースされた 7 つのセキュリティノートが更新されました。
Update to Security Note released on September 2025 Patch Day: [CVE-2025-42944] Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4) Product - SAP Netweaver (RMI-P4) Version - SERVERCORE 7.50 | Critical | ||
Update to Security Note released on September 2025 Patch Day: [CVE-2025-42922] Insecure File Operations vulnerability in SAP NetWeaver AS Java (Deploy Web Service) Product - SAP NetWeaver AS Java (Deploy Web Service) Version - J2EE-APPS 7.50 | Critical | ||
Update to Security Note released on March 2023 Patch Day: [CVE-2023-27500] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform Product – SAP NetWeaver AS for ABAP and ABAP Platform Version – 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757 | Critical | ||
Update to Security Note released on September 2025 Patch Day: [CVE-2025-42917] Missing Authorization check in SAP HCM (Approve Timesheets Fiori 2.0 application) Product - SAP HCM (Approve Timesheets Fiori 2.0 application) Version - GBX01HR5 605 | Medium | ||
Update to Security Note released on September 2025 Patch Day: [CVE-2025-42912] Missing Authorization check in SAP HCM (My Timesheet Fiori 2.0 application) Product - SAP HCM (My Timesheet Fiori 2.0 application) Version - GBX01HR5 605 | Medium | ||
Update to Security Note released on September 2025 Patch Day: [CVE-2025-42915] Missing Authorization Check in Fiori app (Manage Payment Blocks) Product - Fiori app (Manage Payment Blocks) Version - S4CORE 107, 108 | Medium | ||
Update to Security Note released on September 2025 Patch Day: [CVE-2025-42918] Missing Authorization check in SAP NetWeaver Application Server for ABAP (Background Processing) Product - SAP NetWeaver Application Server for ABAP (Background Processing) Version - SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816 | Medium | ||
[CVE-2025-42907] Server-Side Request Forgery in SAP BI Platform Product - SAP BI Platform Version - ENTERPRISE 430, 2025, 2027 | Medium |
今月のセキュリティパッチを提供してきたセキュリティ研究者や調査会社の詳細については、こちらをご覧ください。
SAP は、信頼できる製品とクラウドサービスの提供に尽力しています。安全な運用とデータの完全性を確保するには、安全な設定が不可欠です。そのため、SAP ポートフォリオに最適なセキュリティを設定できるように、この文書に統合されたセキュリティ推奨事項が文書化されています。
過去のアーカイブブログは、こちらからご覧いただけます。
このページに関するコメントまたはフィードバックがある場合は secure@sap.com 宛にご連絡ください。(お問い合わせは英語でお願いいたします。)