Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SAP Security Patch Day – September 2025

SAP has released its September 2025 security patch package containing 26 security notes addressing critical vulnerabilities across enterprise SAP environments. This release includes four HotNews vulnerabilities with CVSS ratings up to 10.0, four High priority issues, sixteen Medium priority fixes, and two Low priority updates. The patches affect NetWeaver AS Java, S/4HANA, SAP HCM, Business Planning and Consolidation, Commerce Cloud, and SAP Business One.

Total Security Notes
26
HotNews Critical
4
High Priority
4
Medium Priority
16
Low Priority
2

Executive Summary

  • Critical Remote Code Execution: Four HotNews vulnerabilities including CVE-2025-42944 (CVSS 10.0) in NetWeaver RMI-P4, CVE-2025-42922 (CVSS 9.9) in Deploy Web Service, and CVE-2025-42958 (CVSS 9.1) with authentication bypass.
  • High-Risk Authorization Failures: Multiple authorization bypass vulnerabilities in Business One SLD (CVSS 8.8), Landscape Transformation (CVSS 8.1), and missing input validation in S/4HANA components.
  • Widespread Medium Issues: Authorization gaps in HCM Fiori apps, XSS in CRM/SRM, DoS in Business Planning, and Spring Security misconfigurations in Commerce Cloud.

Critical HotNews Vulnerabilities

Insecure Deserialization in NetWeaver RMI-P4

10.0 CVE-2025-42944 BC-JAS-COR-RMT Deserialization
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Missing authentication allows unauthenticated access to certain resources.

SAP Note 3619465 — apply patch.

Insecure File Operations in Deploy Web Service

9.9 CVE-2025-42922 BC-JAS-DPL File Operations
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Authenticated attackers can manipulate file operations leading to complete system takeover across connected environments.

SAP Note 3643865 — patch within 48 hours.

Directory Traversal in NetWeaver ABAP Platform

9.6 CVE-2023-27500 BC-DOC-RIT Directory Traversal
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

Critical directory traversal vulnerability allowing authenticated users to manipulate file systems and compromise availability.

SAP Note 3302162 — updated patch September 2025.

Missing Authentication in NetWeaver

9.1 CVE-2025-42958 BC-OP-AS4 Missing Auth
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Missing authentication check allows high-privileged users to escalate across system boundaries with full impact.

SAP Note 3627373 — immediate patching required.

High Priority Security Issues

Insecure Storage in SAP Business One SLD

8.8 CVE-2025-42933 SBO-BC-SLD Insecure Storage
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Sensitive information stored insecurely allows low-privileged users to access and modify critical business data.

SAP Note 3642961 — deploy within 7 days.

Input Validation Flaw in S/4HANA Private Cloud

8.1 CVE-2025-42916 CA-DT-CNV-BAS Input Validation
CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H

Missing input validation in conversion components enables adjacent network attacks affecting integrity and availability.

SAP Note 3635475 — high priority patch.

Input Validation Gap in Landscape Transformation

8.1 CVE-2025-42929 CA-LT-OBT Input Validation
CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H

Landscape Transformation Replication Server vulnerability allows high-privileged users to compromise system integrity.

SAP Note 3633002 — patch within 14 days.

Directory Traversal in Service Data Collection

7.7 CVE-2025-27428 SV-SMG-SDD Directory Traversal
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Directory traversal vulnerability allows authenticated users to access sensitive files outside intended directories.

SAP Note 3581811 — updated September 2025.

Medium Priority Vulnerabilities

Spring Security Misconfiguration in Commerce Cloud

6.6 CVE-2025-22228 CEC-SCC-PLA-PL Misconfiguration
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Security misconfiguration in Spring framework within SAP Commerce Cloud and Datahub.

SAP Note 3620264 — schedule patch.

Missing Authorization in HCM Timesheet Apps

6.5 CVE-2025-42917 PA-FIO-TS Missing Auth
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Missing authorization in SAP HCM Approve Timesheets Fiori 2.0 application.

SAP Note 3643832 — medium priority.

DoS Vulnerability in Business Planning

6.5 CVE-2025-42930 EPM-BPC-NW-SQE Denial of Service
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Authenticated users can cause service disruption in Business Planning and Consolidation.

SAP Note 3614067 — maintenance window.

Outdated JSON Library in BusinessObjects BI

6.5 CVE-2023-5072 BI-BIP-INV DoS
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Outdated JSON library in BusinessObjects BI Platform can lead to denial of service.

SAP Note 3611420 — update library.

XSS in CRM Business Framework

6.1 CVE-2025-42938 CRM-BF-ML XSS
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Cross-site scripting vulnerability in NetWeaver ABAP Platform CRM component.

SAP Note 3629325 — patch available.

XSS in Supplier Relationship Management

6.1 CVE-2025-42920 SRM-EBP-TEC-ITS XSS
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Cross-site scripting vulnerability requiring user interaction in SAP SRM.

SAP Note 3647098 — apply patch.

Authorization Gap in Manage Payment Blocks

5.4 CVE-2025-42915 FI-FIO-AP Missing Auth
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Missing authorization check in Fiori app for managing payment blocks.

SAP Note 3409013 — apply update.

Missing Authentication in NetWeaver AS Java

5.3 CVE-2025-42926 BC-WD-JAV Missing Auth
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Unauthenticated remote code execution via insecure deserialization. Maximum CVSS score indicates complete system compromise without authentication.

SAP Note 3634501 — emergency patch required.

Service Data Download Authorization Gap

5.0 CVE-2025-42911 SV-SMG-SDD Missing Auth
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Missing authorization check in NetWeaver Service Data Download component.

SAP Note 3627644 — schedule update.

Authorization Bypass in ABAP Database Interface

4.9 CVE-2025-42961 BC-DB-DBI Missing Auth
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

High-privileged users can access unauthorized database information.

SAP Note 3610322 — routine update.

CSRF in Manage Work Center Groups

4.3 CVE-2025-42923 PP-BD-WKC CSRF
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Cross-Site Request Forgery vulnerability in SAP Fiori Work Center Groups app.

SAP Note 3450692 — apply fix.

Background Processing Authorization Gap

4.3 CVE-2025-42918 BC-CCM-BTC Missing Auth
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Missing authorization in NetWeaver ABAP background processing component.

SAP Note 3623504 — maintenance patch.

Predictable Object ID in IIOP Service

4.3 CVE-2025-42925 BC-JAS-COR-RMT Predictable ID
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Predictable object identifier vulnerability in NetWeaver AS Java IIOP Service.

SAP Note 3640477 — apply update.

Outdated OpenSSL in Adobe Document Service

3.4 CVE-2025-42927 BC-SRV-FP Info Disclosure
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Information disclosure due to outdated OpenSSL version in NetWeaver AS Java.

SAP Note 3525295 — update OpenSSL.

Low Priority Security Updates

Reverse Tabnabbing in Fiori Launchpad

3.5 CVE-2025-42941 CA-FLP-FE-COR Tabnabbing
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

High-privileged users could be exposed to phishing attacks via tab hijacking.

SAP Note 3624943 — Fiori update cycle.

Resource Release Issue in Commerce Cloud

3.1 CVE-2024-13009 CEC-SCC-PLA-PL Resource Release
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Potential improper resource release vulnerability in SAP Commerce Cloud.

SAP Note 3632154 — regular maintenance.

Explore More

SAP Security Patch Day – August 2025

SAP has released its August 2025 security patch package containing 19 security notes addressing critical vulnerabilities across enterprise SAP environments. This release

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.