We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.
We hope you enjoy using it!
This time we found critical correction advisiories. We count 19 and the highest CVSS score is 9.6.
Severity
SAP© Security advisories 19
System Types
Affected SAP© system types
Affected system
type
ABAP
Patchday
2025-06
Released
on
2025/06/10
Description
[CVE-2025-42989] Missing Authorization check in SAP NetWeaver Application Server for ABAP
Affected system
type
Java
Patchday
2025-06
Released
on
2025/05/13
Description
[CVE-2025-42999] Insecure Deserialization in SAP NetWeaver (Visual Composer development server)
Affected system
type
ABAP
Patchday
2025-06
Released
on
2025/06/10
Description
[CVE-2025-42982] Information Disclosure in SAP GRC (AC Plugin)
Affected system
type
BI/BO platform
Patchday
2025-06
Released
on
2025/01/14
Description
[CVE-2025-0061] Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform
Affected system
type
ABAP
Patchday
2025-06
Released
on
2025/06/10
Description
[CVE-2025-42983] Missing Authorization check in SAP Business Warehouse and SAP Plug-In Basis
Affected system
type
BI/BO platform
Patchday
2025-06
Released
on
2025/06/10
Description
[CVE-2025-23192] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence (BI Workspace)
Affected system
type
ABAP
Patchday
2025-06
Released
on
2025/05/13
Description
[CVE-2025-43011] Missing Authorization Check in SAP Landscape Transformation (PCL Basis)
Affected system
type
ABAP
Patchday
2025-06
Released
on
2025/06/10
Description
[CVE-2025-42977] Directory Traversal vulnerability in SAP NetWeaver Visual Composer
Affected system
type
SAP MDM Server
Patchday
2025-06
Released
on
2025/06/10
Description
[CVE-2025-42994] Multiple vulnerabilities in SAP MDM Server
Affected system
type
ABAP
Patchday
2025-06
Released
on
2025/06/10
Description
[CVE-2025-42993] Missing Authorization Check in SAP S/4HANA (Enterprise Event Enablement)
Affected system
type
ABAP
Patchday
2025-06
Released
on
2025/05/13
Description
[CVE-2025-43008] Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal
Affected system
type
ABAP
Patchday
2025-06
Released
on
2025/06/10
Description
[CVE-2025-31325] Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver (ABAP Keyword Documentation)
Affected system
type
ABAP
Patchday
2025-06
Released
on
2025/06/10
Description
[CVE-2025-42984] Missing Authorization check in SAP S/4HANA (Manage Central Purchase Contract application)
Affected system
type
SAP Business One
Patchday
2025-06
Released
on
2025/06/10
Description
[CVE-2025-42998] Security misconfiguration vulnerability in SAP Business One Integration Framework
Affected system
type
ABAP
Patchday
2025-06
Released
on
2025/06/10
Description
[CVE-2025-42987] Missing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statement)
Affected system
type
ABAP
Patchday
2025-06
Released
on
2025/06/10
Description
[CVE-2025-42991] Missing Authorization check in SAP S/4HANA (Bank Account Application)
Affected system
type
BI/BO platform
Patchday
2025-06
Released
on
2025/06/10
Description
[CVE-2025-42988] Server-Side Request Forgery in SAP Business Objects Business Intelligence Platform
Affected system
type
ABAP
Patchday
2025-06
Released
on
2025/02/11
Description
[CVE-2025-23191] Cache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERP
Affected system
type
SAP UI5
Patchday
2025-06
Released
on
2025/06/10
Description
[CVE-2025-42990] HTML Injection in Unprotected SAPUI5 applications