SAP Security Notes Summary – January 2025

Traditionally once a month I’ll publish a review of all SAP security notes and news that were released in a given month. SAP Security Notes contain SAP’s expert advice regarding important action items and patches to ensure the security of your systems.

SAP ComponentNumberTitleCVSS Score Released On
BI-RA-CRE3492169Multiple Buffer overflow vulnerabilities in SAP BusinessObjects Business Intelligence Platform (Crystal Reports for Enterprise)2,214.01.2025
BC-BMT-WFM3542698[CVE-2025-0058] Information Disclosure vulnerability in SAP Business Workflow and SAP Flexible Workflow6,514.01.2025
BC-FES-JAV3502459[CVE-2025-0056] Information Disclosure vulnerability in SAP GUI for Java6,014.01.2025
BC-FES-GUI3472837[CVE-2025-0055] Information Disclosure vulnerability in SAP GUI for Windows6,014.01.2025
BC-MID-ICF3536461[CVE-2025-0053] Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform5,314.01.2025
BC-WD-JAV3540108[CVE-2025-0067] Missing Authorization check in SAP NetWeaver Application Server Java6,314.01.2025
BC-MID-ICF3537476[CVE-2025-0070] Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform9,914.01.2025
BC-JAS-SEC-UME3514421[CVE-2025-0057] Cross-Site Scripting vulnerability in SAP NetWeaver AS JAVA (User Admin Application)4,814.01.2025
BI-BIP-INV3474398[CVE-2025-0061] Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform8,714.01.2025
BC-DB-INF3550816[CVE-2025-0063] SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform8,814.01.2025
BC-MID-ICF3550708[CVE-2025-0066] Information Disclosure vulnerability in  SAP NetWeaver AS for ABAP and ABAP Platform(Internet Communication Framework)9,914.01.2025
BC-BMT-WFM3550674[CVE-2025-0068] Missing Authorization check in Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP4,314.01.2025
BC-FES-INS3542533[CVE-2025-0069] DLL Hijacking vulnerability in SAPSetup7,814.01.2025
BC-FES-WGU3503138[CVE-2025-0059] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML)6,014.01.2025

*The characteristics of a vulnerability and produce a numerical score reflecting its severity. The numerical score can then be translated into a qualitative representation (such as low, medium, high, and critical) to help organizations properly assess and prioritize their vulnerability management processes.

Copyright © 2025. SAPBasisWorld.com Privacy Policy