Advisory
On 09.09.2025 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAP Fiori.
SAP Note 3450692 addresses "[CVE-2025-42923] Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App (F4044 Manage Work Center Groups)" to prevent cross-site request forgery (xsrf) with a medium risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process, the team suggests.
Risk specification
SAP Fiori App (F4044 Manage Work Center Groups) allows unauthenticated attackers to trick authenticated users into sending crafted requests, causing unintended actions on their behalf.Solution
All state-changing function imports are now corrected to prevent unintended actions.
- 9.9 [CVE-2021-33690] Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure (Component Build Service)
- 7.6 [CVE-2020-6275] Server Side Request Forgery vulnerability in SAP NetWeaver AS ABAP
- 6.8 [CVE-2025-24875] SameSite Defense in Depth not applied for some cookies in SAP Commerce
- 6.3 Cross-Site Request Forgery (CSRF) vulnerability in multiple SAP Sybase products
- 5.5 Cross-Site Request Forgery (CSRF) vulnerability in Cash Management
