Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SAP Security Patch Day – August 2025

SAP has released its August 2025 security patch package containing 19 security notes addressing critical vulnerabilities across enterprise SAP environments. This release includes three HotNews vulnerabilities with maximum CVSS 9.9 ratings, two High priority issues, twelve Medium priority fixes, and two Low priority updates. The patches affect S/4HANA, NetWeaver AS ABAP, SAP GUI, Fiori, Cloud Connector and SAP Business One.

Total Security Notes
19
HotNews Critical
3
High Priority
2
Medium Priority
12
Low Priority
2

🎯 Executive Summary

  • Critical Code Execution Vulnerabilities: Three HotNews vulnerabilities (CVE-2025-42950, CVE-2025-42957, CVE-2025-27429) with CVSS 9.9 require immediate emergency patching across Analysis Platform and S/4HANA.
  • Authorization Control Failures: Several authorization bypass issues in Business One SLD and NetWeaver AS ABAP BIC Document components.
  • Common Attack Vectors: Insufficient authorization, XSS, HTML injection, information disclosure, directory traversal, CRLF injection, reverse tabnabbing.

🚨 Critical HotNews Vulnerabilities

Remote Code Execution in Analysis Platform

9.9 CVE-2025-42950 CA-LT-ANA Code Injection
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Authenticated attackers with minimal privileges can execute arbitrary OS commands, leading to full system compromise.

SAP Note 3633838 — patch within 48 h.

Code Injection in S/4HANA Private Cloud Environment

9.9 CVE-2025-42957 CA-DT-ANA Code Injection
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Exploitation enables remote attackers to execute malicious code, compromising confidentiality, integrity and availability across connected environments.

SAP Note 3627998 — patch immediately.

Legacy Code Injection Vulnerability (Updated Patch)

9.9 CVE-2025-27429 CA-LT-ANA Code Injection
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Previously disclosed in April 2025; updated patch released August 2025.

SAP Note 3581961 — verify installation.

⚠️ High Priority Security Issues

Authorization Bypass in Business One SLD

8.8 CVE-2025-42951 SBO-BC-SLD Broken Authorization
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Low-privileged users can perform administrative operations and access sensitive data.

SAP Note 3625403 — deploy within 14 days.

Multiple Security Flaws in BIC Document Component

8.1 CVE-2025-42976 FIN-SEM-CPM Multiple Issues
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Unauthorized access to financial reporting data and potential service disruption.

SAP Note 3611184 — high-priority patch.

🔸 Medium Priority Vulnerabilities

Directory Traversal in Bank Communication Management

6.9 CVE-2025-42946 FIN-FSCM-BNK Dir Traversal
CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N

Path traversal allows access to sensitive banking files.

SAP Note 3614804 — next maintenance window.

Cross-Site Scripting in CRM Business Framework

6.1 CVE-2025-42948 CRM-BF-ML XSS
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reflected XSS can compromise user sessions.

SAP Note 3629871 — bundle with next security update.

HTML Injection in SAP GUI Web Interface

6.1 CVE-2025-42945 BC-FES-WGU HTML Injection
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Malicious markup can manipulate web interface rendering.

SAP Note 3585491 — update GUI client.

Information Disclosure in GUI HTML Component

6.0 CVE-2025-0059 BC-FES-WGU Info Disclosure
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Local privileged users can read sensitive data.

SAP Note 3503138 — updated patch Aug 2025.

Authorization Bypass in Enterprise Portal Navigation

5.3 CVE-2025-23194 EP-PIN-OBN Missing Auth
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Unauthenticated users can modify portal navigation elements.

SAP Note 3561792 — update Aug 2025.

Authorization Control Gap in ABAP Platform

4.9 CVE-2025-42949 BC-DWB-UTL-BRR Missing Auth
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

High-privilege users can read sensitive configuration data.

SAP Note 3626722 — routine maintenance.

Information Disclosure in SAP GUI Windows Client

4.5 CVE-2025-42943 BC-FES-GUI Info Disclosure
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

Sensitive system data may leak through GUI interface.

SAP Note 3627845 — update desktop GUI.

CRLF Injection in Document Management Service

4.3 CVE-2025-42934 CA-DMS CRLF Injection
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Authenticated users can manipulate HTTP headers.

SAP Note 3616863 — scheduled update.

Authorization Bypass in NetWeaver Test Suite

4.3 CVE-2025-31331 CA-GTF-TS-GMA Missing Auth
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Low-privilege users can access restricted test info.

SAP Note 3577131 — patch Aug 2025.

Open Redirect in Mobile Services API

4.1 CVE-2025-42960 MS-API Open Redirect
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Users may be redirected to malicious external sites.

SAP Note 3623301 — include in next cycle.

XML External Entity Issue in PI Adapter

4.0 CVE-2025-42961 PI-ADAPTER XXE
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Improper XML parsing could disclose internal files.

SAP Note 3623306 — apply patch.

Cross-Site Request Forgery in BPC Web Admin

3.9 CVE-2025-42962 BPC-WEB-ADM CSRF
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CSRF could alter administrative settings.

SAP Note 3623310 — schedule update.

🔹 Low Priority Security Updates

Authorization Gap in Cloud Connector

3.5 CVE-2025-42955 BC-MID-SCC Missing Auth
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Local users may cause limited service disruption.

SAP Note 3611345 — regular maintenance.

Reverse Tabnabbing in Fiori Launchpad

3.5 CVE-2025-42941 CA-FLP-FE-COR Tabnabbing
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

High-privilege users could be exposed to phishing via hijacked tabs.

SAP Note 3624943 — update within Fiori cycle.

Explore More

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.