We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 14 and the highest CVSS score is 9.6.

 

Severity
SAP© Security advisories 14
 System Types
Affected SAP© system types

 

3600840
CVSS
9.6

Affected system type ABAP
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42989] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3604119
CVSS
9.1

Affected system type Java
Patchday 2025-06
Released on 2025/05/13
Description [CVE-2025-42999] Insecure Deserialization in SAP NetWeaver (Visual Composer development server)
3609271
CVSS
8.8

Affected system type ABAP
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42982] Information Disclosure in SAP GRC (AC Plugin)
3474398
CVSS
8.7

Affected system type BI/BO platform
Patchday 2025-06
Released on 2025/01/14
Description [CVE-2025-0061] Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform
3606484
CVSS
8.5

Affected system type ABAP
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42983] Missing Authorization check in SAP Business Warehouse and SAP Plug-In Basis
3560693
CVSS
8.2

Affected system type BI/BO platform
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-23192] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence (BI Workspace)
3591978
CVSS
7.7

Affected system type ABAP
Patchday 2025-06
Released on 2025/05/13
Description [CVE-2025-43011] Missing Authorization Check in SAP Landscape Transformation (PCL Basis)
3610006
CVSS
7.5

Affected system type SAP MDM Server
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42994] Multiple vulnerabilities in SAP MDM Server
3590887
CVSS
5.8

Affected system type ABAP
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-31325] Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver (ABAP Keyword Documentation)
3594258
CVSS
5.3

Affected system type SAP Business One
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42998] Security misconfiguration vulnerability in SAP Business One Integration Framework
3608058
CVSS
4.3

Affected system type ABAP
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42991] Missing Authorization check in SAP S/4HANA (Bank Account Application)
3596850
CVSS
4.3

Affected system type ABAP
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42987] Missing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statement)
3585545
CVSS
3.7

Affected system type BI/BO platform
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42988] Server-Side Request Forgery in SAP Business Objects Business Intelligence Platform
3601169
CVSS
3.0

Affected system type SAP UI5
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42990] HTML Injection in Unprotected SAPUI5 applications