SAP Security Notes Summary – March 2025
Traditionally once a month I’ll publish a review of all SAP security notes and news that were released in a given month. SAP Security Notes contain SAP’s expert advice regarding important action items and patches to ensure the security of your systems.
| SAP Component | Number | Title | CVSS Score | Released On |
|---|---|---|---|---|
| CRM-IC-BF | 3561861 | [CVE-2025-27430] Server Side Request Forgery (SSRF) in SAP CRM and SAP S/4 HANA (Interaction Center) | 3,5 | 25.03.2025 |
| BC-CP-CF-CRTM | 3576540 | Open Source Security Advisory: Best Practices for Securing Spring Boot Actuator Endpoints for applications running on BTP | 0,0 | 11.03.2025 |
| CEC-SCC-PLA-PL | 3562415 | [CVE-2024-38819] Multiple vulnerabilities in Spring Framework within SAP Commerce Cloud and SAP Datahub | 3,7 | 11.03.2025 |
| BI-BIP-LCM | 3549494 | [CVE-2025-23185] Information Disclosure in SAP Business Objects Business Intelligence Platform | 4,1 | 11.03.2025 |
| BI-RA-WBI-FE-HTM | 3557459 | [CVE-2025-0062] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) | 4,7 | 11.03.2025 |
| BI-RA-WBI-FE-HTM | 3557469 | [CVE-2025-25245] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) | 5,4 | 11.03.2025 |
| CEC-SCC-COM-BBA-COM | 3566851 | [CVE-2024-38286] Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud | 8,6 | 11.03.2025 |
| MM-FIO-PUR-IR | 3474392 | [CVE-2025-26656] Missing Authorization check in S/4HANA (Manage Purchasing Info Records) | 4,3 | 11.03.2025 |
| FI-FIO-AR-PAY | 3565835 | [CVE-2025-27433] Broken Access Control vulnerabilities in SAP S/4HANA (Manage Bank Statements) | 4,3 | 11.03.2025 |
| EP-PIN-OBN | 3561792 | [CVE-2025-23194] Missing Authentication check in SAP NetWeaver Enterprise Portal (OBN component) | 5,3 | 11.03.2025 |
| BC-WD-UR | 3567246 | [CVE-2025-27431] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java | 5,4 | 11.03.2025 |
| CEC-SCC-COM-BC-BCOM | 3569602 | [CVE-2025-27434] Cross-Site Scripting (XSS) vulnerability in SAP Commerce (Swagger UI) | 8,8 | 11.03.2025 |
| FI-FIO-GL-TRA | 3557655 | [CVE-2025-26660] Broken Access Control in SAP Fiori apps (Posting Library) | 4,3 | 11.03.2025 |
| BC-FES-WGU | 3552824 | [CVE-2025-26659] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML) | 6,1 | 11.03.2025 |
| BC-FES-WGU | 3562390 | [CVE-2025-25242] Cross-Site Scripting (XSS) in SAP NetWeaver Application Server ABAP | 6,1 | 11.03.2025 |
| BC-DWB-TOO-CLA | 3563927 | [CVE-2025-26661] Missing Authorization check in SAP NetWeaver (ABAP Class Builder) | 8,8 | 11.03.2025 |
| FS-RBD | 3557131 | [CVE-2025-23188] Missing Authorization check in SAP S/4HANA (RBD) | 4,3 | 11.03.2025 |
| CA-GTF-CSC-EDO | 3568865 | [CVE-2025-27432] Missing Authorization check in SAP Electronic Invoicing for Brazil (eDocument Cockpit) | 2,4 | 11.03.2025 |
| BW-WHM-DST-PC | 3552144 | [CVE-2025-25244] Missing Authorization Check in SAP Business Warehouse (Process Chains) | 5,7 | 11.03.2025 |
| SBO-CRO-SEC | 3561045 | [CVE-2025-26658] Broken Authentication in SAP Business One (Service Layer) | 6,8 | 11.03.2025 |
| BC-CST-IC | 3558132 | [CVE-2025-0071] Information Disclosure vulnerability in SAP Web Dispatcher and Internet Communication Manager | 4,9 | 11.03.2025 |
| FIN-BA | 3483344 | [CVE-2024-39592] Missing Authorization check in SAP PDCE | 7,7 | 11.03.2025 |
| BC-XS-APR | 3567974 | [CVE-2025-24876] Authentication bypass via authorization code injection in SAP Approuter | 8,1 | 11.03.2025 |
*The characteristics of a vulnerability and produce a numerical score reflecting its severity. The numerical score can then be translated into a qualitative representation (such as low, medium, high, and critical) to help organizations properly assess and prioritize their vulnerability management processes.
