We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.
We hope you enjoy using it!
This time we found critical correction advisiories. We count 24 and the highest CVSS score is 10.0.
Severity
SAP© Security advisories 24
System Types
Affected SAP© system types
Affected system
type
Java
Patchday
2025-11
Released
on
2025/10/14
Description
[CVE-2025-42944] Security Hardening for Insecure Deserialization in SAP NetWeaver AS Java
Affected system
type
Sybase platform
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42890] Insecure key & Secret Management vulnerability in SQL Anywhere Monitor (Non-Gui)
Affected system
type
ABAP
Patchday
2025-11
Released
on
2025/10/14
Description
[CVE-2025-42910] Unrestricted File Upload Vulnerability in SAP Supplier Relationship Management
Affected system
type
SAP Commerce Cloud
Patchday
2025-11
Released
on
2025/10/14
Description
[CVE-2025-5115] Denial of service (DOS) in SAP Commerce Cloud (Search and Navigation)
Affected system
type
ABAP Java HANA platform
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42940] Memory Corruption vulnerability in SAP CommonCryptoLib
Affected system
type
SAP HANA Client
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42895 ] Code Injection vulnerability in SAP HANA JDBC Client
Affected system
type
SAP Business Connector
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42894] Path Traversal vulnerability in SAP Business Connector
Affected system
type
SAP Business Connector
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42892] OS Command Injection vulnerability in SAP Business Connector
Affected system
type
Java
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42884] JNDI Injection vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
SAP Business Connector
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42893] Open Redirect vulnerability in SAP Business Connector
Affected system
type
SAP Business Connector
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42886] Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector
Affected system
type
ABAP
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42924] Open Redirect vulnerabilities in SAP S/4HANA landscape (SAP E-Recruiting BSP)
Affected system
type
ABAP
Patchday
2025-11
Released
on
2025/08/12
Description
[CVE-2025-42942] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP
Affected system
type
SAP HANA Platform
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42885] Missing authentication in SAP HANA 2.0 (hdbrss)
Affected system
type
SAP GUI / Frontend
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42888] Information Disclosure vulnerability in SAP GUI for Windows
Affected system
type
ABAP
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42889] SQL Injection vulnerability in SAP Starter Solution (PL SAFT)
Affected system
type
Java
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42919] Information Disclosure vulnerability in SAP NetWeaver Application Server Java
Affected system
type
SAP Business One
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42897] Information Disclosure vulnerability in SAP Business One (SLD)
Affected system
type
ABAP
Patchday
2025-11
Released
on
2025/09/09
Description
[CVE-2025-42911] Missing Authorization check in SAP NetWeaver (Service Data Download)
Affected system
type
ABAP
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42899] Missing Authorization check in SAP S4CORE (Manage Journal Entries)
Affected system
type
ABAP
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42882] Missing Authorization check in SAP NetWeaver Application Server for ABAP
Affected system
type
BI/BO platform
Patchday
2025-11
Released
on
2025/10/14
Description
[CVE-2025-31672] Deserialization Vulnerability in SAP BusinessObjects (Web Intelligence and Platform Search)
Affected system
type
ABAP
Patchday
2025-11
Released
on
2025/02/11
Description
[CVE-2025-23191] Cache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERP
Affected system
type
ABAP
Patchday
2025-11
Released
on
2025/11/11
Description
[CVE-2025-42883] Insecure File Operations vulnerability in SAP NetWeaver Application Server for ABAP (Migration Workbench)