[Action required] SAP Security out-of-bound patch - 22 July 2025 
Advisory

SAP out-of-bound Patch released

 

Subject:
Today SAP released 3 out-of-band patch(-es) with a MEDIUM priority that might require attention.
Please review them via SecurityBridge Patch Management and validate against your environment.

Patch Details:

SAP Component Number Title BC-FES-ITS 3617131 [CVE-2025-42981] Multiple vulnerabilities in SAP NetWeaver Application Server ABAP FI-LOC-CA-XX 3540688 [CVE-2025-42947] Code Injection vulnerability in SAP FICA ODN framework PY-PT 3585992 [CVE-2025-43008] Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal

The SecurityBridge Team has taken swift action by updating the cloud backbone with the latest security patches as a proactive measure. If you are a SecurityBridge customer, we highly encourage you to initiate the validation process using the Patch Management Application to identify the most relevant patches for your specific environment.

At SecurityBridge, we prioritize the security of your environment and understand its significance. Our streamlined validation process aims to provide tailored guidance, recognizing the unique nature of each customer's environment. We are dedicated to assisting you in selecting the most appropriate patches that align with your system's specific requirements.

  • Share with:
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2025 by SecurityBridge GmbH

v38.6