SAP Security Notes Summary – February 2025
Traditionally once a month I’ll publish a review of all SAP security notes and news that were released in a given month. SAP Security Notes contain SAP’s expert advice regarding important action items and patches to ensure the security of your systems.
SAP Component | Number | Title | CVSS Score | Released On |
---|---|---|---|---|
PM-FIO-WCM | 3475427 | [CVE-2024-41736] Information Disclosure vulnerability in SAP Permit to Work | 4,3 | 26.02.2025 |
IS-A-JIT | 3347991 | [CVE-2025-26655] Missing Authorization check in SAP JIT(Outbound) | 3,1 | 25.02.2025 |
BC-UPG-ADDON | 3553753 | [CVE-2025-24872] Missing Authorization check in SAP ABAP Platform (ABAP Build Framework) | 4,3 | 11.02.2025 |
OPU-GW-COR | 3426825 | [CVE-2025-23191] Cache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERP | 3,1 | 11.02.2025 |
BI-BIP-AUT | 3525794 | [CVE-2025-0064] Improper Authorization in SAP BusinessObjects Business Intelligence platform (Central Management Console) | 8,7 | 11.02.2025 |
EP-PDK-HBJ | 3526203 | [CVE-2025-0054] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java | 5,4 | 11.02.2025 |
CEC-SCC-COM-SRC-SER | 3540273 | [CVE-2024-45216] Multiple vulnerabilities in Apache Solr within SAP Commerce Cloud | 5,5 | 11.02.2025 |
PA-FIO-OVT | 3532025 | [CVE-2025-25241] Missing Authorization check in SAP Fiori Apps Reference Library (My Overtime Requests) | 5,4 | 11.02.2025 |
BC-JAS-SEC-UME | 3417627 | [CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application) | 8,8 | 11.02.2025 |
CEC-SCC-CDM-BO-FRW | 3555364 | [CVE-2025-24875] SameSite Defense in Depth not applied for some cookies in SAP Commerce | 6,8 | 11.02.2025 |
BC-WD-JAV | 3550027 | [CVE-2025-24869] Information Disclosure vulnerability in SAP NetWeaver Application Server Java | 4,3 | 11.02.2025 |
SV-SMG-TWB | 3547581 | [CVE-2025-23190] Missing Authorization check in SAP NetWeaver and ABAP platform (ST-PI) | 4,3 | 11.02.2025 |
SV-SMG-SDD | 3546470 | [CVE-2025-23187] Missing Authorization Check in SAP NetWeaver and ABAP Platform (SDCCN) | 5,3 | 11.02.2025 |
SRM-CAT-MDM | 3567551 | [CVE-2025-25243] Path traversal vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog) | 8,6 | 11.02.2025 |
CA-EPC | 3567172 | [CVE-2024-38819] Multiple vulnerabilities in SAP Enterprise Project Connection | 7,5 | 11.02.2025 |
BI-BIP-INV | 3445708 | [CVE-2025-24867] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform (BI Launchpad) | 6,1 | 11.02.2025 |
BC-XS-SEC | 3563929 | [CVE-2025-24868] Open Redirect Vulnerability in SAP HANA extended application services, advanced model (User Account and Authentication Services) | 7,1 | 11.02.2025 |
BC-FES-GUI | 3562336 | [CVE-2025-24870] Insecure Key & Secret Management vulnerability in SAP GUI for Windows | 6,0 | 11.02.2025 |
BC-BMT-WFM | 3561264 | [CVE-2025-23193] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP | 5,3 | 11.02.2025 |
CEC-SCC-CDM-BO-FRW | 3559510 | [CVE-2025-24874] Missing Defense in Depth Against Clickjacking in SAP Commerce (Backoffice) | 6,8 | 11.02.2025 |
BC-JAS-DPL | 3287784 | [CVE-2023-24527] Improper Access Control in SAP NetWeaver AS Java for Deploy Service | 5,3 | 11.02.2025 |
BC-JAS-SEC-UME | 3557138 | Update 1 to Security Note 3417627 – [CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application) | 6,1 | 11.02.2025 |
*The characteristics of a vulnerability and produce a numerical score reflecting its severity. The numerical score can then be translated into a qualitative representation (such as low, medium, high, and critical) to help organizations properly assess and prioritize their vulnerability management processes.