Advisory
On 12.08.2025 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAP Business One.
SAP Note 3625403 addresses "[CVE-2025-42951] Broken Authorization in SAP Business One (SLD)" to prevent missing authorization check with a high risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process, the team suggests.
Risk specification
In SAP Business One (SLD), a missing authorization check in an API allows an authenticated attacker to access sensitive credentials and gain database administrator privileges.Solution
The issue has been mitigated by revoking API permissions for standard SAP Business One users, enforcing appropriate database access privileges, and requiring administrator login for landscape management tasks.
- 9.9 [CVE-2022-41272] Improper access control in SAP NetWeaver AS Java (User Defined Search)
- 9.4 [CVE-2022-41271] Improper access control in SAP NetWeaver AS Java (Messaging System)
- 6.3 [CVE-2020-6212] Missing Authorization Check in SAP ERP & S/4 HANA (Egypt localized Withholding Tax reports)
- 4.3 [CVE-2025-31331] Authorization Bypass vulnerability in SAP NetWeaver