[Action required] SAP Security out-of-bound patch - 25 April 2025 
Advisory

SAP out-of-bound Patch released

 

SAP released out-of-bound patch(-es) that require attention. Please download these using SecurityBridge Patch Management and verify which updates apply to your installed base.


The details of these patches are:


Note 3594142

[CVE-2025-31324] Missing Authorization check in SAP NetWeaver (Visual Composer development server)

CVSS v3.0 Base Score: 10,0 / 10

High priority


Note 3446649

[CVE-2025-31328] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4 HANA (Learning Solution)

CVSS v3.0 Base Score: 4,6 / 10

Low priority


Note 3359825

[CVE-2025-31327] OData meta-data property entity tampering in SAP Field Logistics

CVSS v3.0 Base Score: 4,3 / 10

Low priority


Keeping your systems up to date with the latest security patches is vital to minimize future vulnerabilities.


The SecurityBridge Team has taken swift action by updating the cloud backbone with the latest security patches as a proactive measure. If you are a SecurityBridge customer, we highly encourage you to initiate the validation process using the Patch Management Application to identify the most relevant patches for your specific environment.


At SecurityBridge, we prioritize the security of your environment and understand its significance. Our streamlined validation process aims to provide tailored guidance, recognizing the unique nature of each customer's environment. We are dedicated to assisting you in selecting the most appropriate patches that align with your system's specific requirements.

  • Share with:
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2025 by SecurityBridge GmbH

v37.4