We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.
We hope you enjoy using it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 19 and the highest CVSS score is 9.6.

 

 Severity
SAP© Security advisories 19
 System Types
Affected SAP© system types

 

Related note
3600840
CVSS
9.6

Affected system type
ABAP
Patchday
2025-06
Released on
2025/06/10

Description
[CVE-2025-42989] Missing Authorization check in SAP NetWeaver Application Server for ABAP

 

Related note
3604119
CVSS
9.1

Affected system type
Java
Patchday
2025-06
Released on
2025/05/13

Description
[CVE-2025-42999] Insecure Deserialization in SAP NetWeaver (Visual Composer development server)

 

Related note
3609271
CVSS
8.8

Affected system type
ABAP
Patchday
2025-06
Released on
2025/06/10

Description
[CVE-2025-42982] Information Disclosure in SAP GRC (AC Plugin)

 

Related note
3474398
CVSS
8.7

Affected system type
BI/BO platform
Patchday
2025-06
Released on
2025/01/14

Description
[CVE-2025-0061] Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform

 

Related note
3606484
CVSS
8.5

Affected system type
ABAP
Patchday
2025-06
Released on
2025/06/10

Description
[CVE-2025-42983] Missing Authorization check in SAP Business Warehouse and SAP Plug-In Basis

 

Related note
3560693
CVSS
8.2

Affected system type
BI/BO platform
Patchday
2025-06
Released on
2025/06/10

Description
[CVE-2025-23192] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence (BI Workspace)

 

Related note
3591978
CVSS
7.7

Affected system type
ABAP
Patchday
2025-06
Released on
2025/05/13

Description
[CVE-2025-43011] Missing Authorization Check in SAP Landscape Transformation (PCL Basis)

 

Related note
3610591
CVSS
7.6

Affected system type
ABAP
Patchday
2025-06
Released on
2025/06/10

Description
[CVE-2025-42977] Directory Traversal vulnerability in SAP NetWeaver Visual Composer

 

Related note
3610006
CVSS
7.5

Affected system type
SAP MDM Server
Patchday
2025-06
Released on
2025/06/10

Description
[CVE-2025-42994] Multiple vulnerabilities in SAP MDM Server

 

Related note
3580384
CVSS
6.7

Affected system type
ABAP
Patchday
2025-06
Released on
2025/06/10

Description
[CVE-2025-42993] Missing Authorization Check in SAP S/4HANA (Enterprise Event Enablement)

 

Related note
3585992
CVSS
5.8

Affected system type
ABAP
Patchday
2025-06
Released on
2025/05/13

Description
[CVE-2025-43008] Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal

 

Related note
3590887
CVSS
5.8

Affected system type
ABAP
Patchday
2025-06
Released on
2025/06/10

Description
[CVE-2025-31325] Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver (ABAP Keyword Documentation)

 

Related note
3441087
CVSS
5.4

Affected system type
ABAP
Patchday
2025-06
Released on
2025/06/10

Description
[CVE-2025-42984] Missing Authorization check in SAP S/4HANA (Manage Central Purchase Contract application)

 

Related note
3594258
CVSS
5.3

Affected system type
SAP Business One
Patchday
2025-06
Released on
2025/06/10

Description
[CVE-2025-42998] Security misconfiguration vulnerability in SAP Business One Integration Framework

 

Related note
3596850
CVSS
4.3

Affected system type
ABAP
Patchday
2025-06
Released on
2025/06/10

Description
[CVE-2025-42987] Missing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statement)

 

Related note
3608058
CVSS
4.3

Affected system type
ABAP
Patchday
2025-06
Released on
2025/06/10

Description
[CVE-2025-42991] Missing Authorization check in SAP S/4HANA (Bank Account Application)

 

Related note
3585545
CVSS
3.7

Affected system type
BI/BO platform
Patchday
2025-06
Released on
2025/06/10

Description
[CVE-2025-42988] Server-Side Request Forgery in SAP Business Objects Business Intelligence Platform

 

Related note
3426825
CVSS
3.1

Affected system type
ABAP
Patchday
2025-06
Released on
2025/02/11

Description
[CVE-2025-23191] Cache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERP

 

Related note
3601169
CVSS
3.0

Affected system type
SAP UI5
Patchday
2025-06
Released on
2025/06/10

Description
[CVE-2025-42990] HTML Injection in Unprotected SAPUI5 applications

 

 
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2025 by SecurityBridge GmbH

v38.4