We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.
We hope you enjoy using it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 24 and the highest CVSS score is 10.0.

 

 Severity
SAP© Security advisories 24
 System Types
Affected SAP© system types

 

Related note
3660659
CVSS
10.0

Affected system type
Java
Patchday
2025-11
Released on
2025/10/14

Description
[CVE-2025-42944] Security Hardening for Insecure Deserialization in SAP NetWeaver AS Java

 

Related note
3666261
CVSS
10.0

Affected system type
Sybase platform
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42890] Insecure key & Secret Management vulnerability in SQL Anywhere Monitor (Non-Gui)

 

Related note
3647332
CVSS
9.0

Affected system type
ABAP
Patchday
2025-11
Released on
2025/10/14

Description
[CVE-2025-42910] Unrestricted File Upload Vulnerability in SAP Supplier Relationship Management

 

Related note
3664466
CVSS
7.5

Affected system type
SAP Commerce Cloud
Patchday
2025-11
Released on
2025/10/14

Description
[CVE-2025-5115] Denial of service (DOS) in SAP Commerce Cloud (Search and Navigation)

 

Related note
3633049
CVSS
7.5

Affected system type
ABAP Java HANA platform
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42940] Memory Corruption vulnerability in SAP CommonCryptoLib

 

Related note
3643385
CVSS
6.9

Affected system type
SAP HANA Client
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42895 ] Code Injection vulnerability in SAP HANA JDBC Client

 

Related note
3666038
CVSS
6.8

Affected system type
SAP Business Connector
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42894] Path Traversal vulnerability in SAP Business Connector

 

Related note
3665900
CVSS
6.8

Affected system type
SAP Business Connector
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42892] OS Command Injection vulnerability in SAP Business Connector

 

Related note
3660969
CVSS
6.5

Affected system type
Java
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42884] JNDI Injection vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3662000
CVSS
6.1

Affected system type
SAP Business Connector
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42893] Open Redirect vulnerability in SAP Business Connector

 

Related note
3665907
CVSS
6.1

Affected system type
SAP Business Connector
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42886] Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector

 

Related note
3642398
CVSS
6.1

Affected system type
ABAP
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42924] Open Redirect vulnerabilities in SAP S/4HANA landscape (SAP E-Recruiting BSP)

 

Related note
3597355
CVSS
6.1

Affected system type
ABAP
Patchday
2025-11
Released on
2025/08/12

Description
[CVE-2025-42942] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP

 

Related note
3639264
CVSS
5.8

Affected system type
SAP HANA Platform
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42885] Missing authentication in SAP HANA 2.0 (hdbrss)

 

Related note
3651097
CVSS
5.5

Affected system type
SAP GUI / Frontend
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42888] Information Disclosure vulnerability in SAP GUI for Windows

 

Related note
2886616
CVSS
5.4

Affected system type
ABAP
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42889] SQL Injection vulnerability in SAP Starter Solution (PL SAFT)

 

Related note
3643603
CVSS
5.3

Affected system type
Java
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42919] Information Disclosure vulnerability in SAP NetWeaver Application Server Java

 

Related note
3652901
CVSS
5.3

Affected system type
SAP Business One
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42897] Information Disclosure vulnerability in SAP Business One (SLD)

 

Related note
3627644
CVSS
5.0

Affected system type
ABAP
Patchday
2025-11
Released on
2025/09/09

Description
[CVE-2025-42911] Missing Authorization check in SAP NetWeaver (Service Data Download)

 

Related note
3530544
CVSS
4.3

Affected system type
ABAP
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42899] Missing Authorization check in SAP S4CORE (Manage Journal Entries)

 

Related note
3643337
CVSS
4.3

Affected system type
ABAP
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42882] Missing Authorization check in SAP NetWeaver Application Server for ABAP

 

Related note
3617142
CVSS
3.5

Affected system type
BI/BO platform
Patchday
2025-11
Released on
2025/10/14

Description
[CVE-2025-31672] Deserialization Vulnerability in SAP BusinessObjects (Web Intelligence and Platform Search)

 

Related note
3426825
CVSS
3.1

Affected system type
ABAP
Patchday
2025-11
Released on
2025/02/11

Description
[CVE-2025-23191] Cache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERP

 

Related note
3634053
CVSS
2.7

Affected system type
ABAP
Patchday
2025-11
Released on
2025/11/11

Description
[CVE-2025-42883] Insecure File Operations vulnerability in SAP NetWeaver Application Server for ABAP (Migration Workbench)

 

 
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2025 by SecurityBridge GmbH

v39.26