SAP Security Notes Summary – May 2025

Traditionally, once a month I’ll publish a review of all SAP security notes and news that were released in a given month. SAP Security Notes contain SAP’s expert advice regarding important action items and patches to ensure the security of your systems.

SAP ComponentNumberTitleCVSS Score Released On
EP-VC-INF3604119[CVE-2025-42999] Insecure Deserialization in SAP NetWeaver (Visual Composer development server)9,114.05.2025
EP-VC-INF3594142[CVE-2025-31324] Missing Authorization check in SAP NetWeaver (Visual Composer development server)10,013.05.2025
FIN-BA3483344[CVE-2024-39592] Missing Authorization check in SAP PDCE7,713.05.2025
CA-LT-PCL3591978[CVE-2025-43011] Missing Authorization Check in SAP Landscape Transformation (PCL Basis)7,713.05.2025
SRM-LA3578900[CVE-2025-30018] Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)8,613.05.2025
SRM-CAT-MDM3588455[CVE-2025-43006] Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog)6,113.05.2025
EIM-DS-SVR3558755[CVE-2025-26662] Cross-Site Scripting (XSS) vulnerability in the SAP Data Services Management Console4,413.05.2025
PY-PT3585992[CVE-2025-43008] Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal5,813.05.2025
SCM-BAS-MDL3600859[CVE-2025-43010] Code injection vulnerability in SAP S/4HANA Cloud Private Edition or On Premise(SCM Master Data Layer (MDL))8,313.05.2025
BC-FES-GXT3574520[CVE-2025-43005] Information Disclosure vulnerability in SAP GUI for Windows4,313.05.2025
OPU-GW-V43577300[CVE-2025-42997] Information Disclosure vulnerability in SAP Gateway Client6,613.05.2025
MFG-DM3571096[CVE-2025-43004] Security Misconfiguration Vulnerability in SAP Digital Manufacturing (Production Operator Dashboard)5,313.05.2025
CRM-MD-BP3596033[CVE-2025-43003] Information Disclosure vulnerability in SAP S/4HANA (Private Cloud & On-Premise)6,413.05.2025
LO-SPM-X2719724[CVE-2025-43007] Missing Authorization check in SAP Service Parts Management (SPM)6,313.05.2025
LO-SPM-OUT2491817[CVE-2025-43009] Missing Authorization check in SAP Service Parts Management (SPM)6,313.05.2025
MM-PUR-SVC-SES3227940[CVE-2025-43002] Missing Authorization check in SAP S4/HANA (OData meta-data property)4,313.05.2025
BC-MID-RFC3577287[CVE-2025-31329] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and  ABAP Platform6,213.05.2025
BI-BIP-LCM3586013[CVE-2025-43000] Information Disclosure Vulnerability in SAP Business Objects Business Intelligence Platform (PMW)7,913.05.2025

*The characteristics of a vulnerability and produce a numerical score reflecting its severity. The numerical score can then be translated into a qualitative representation (such as low, medium, high, and critical) to help organizations properly assess and prioritize their vulnerability management processes.

Copyright © 2026. SAPBasisWorld.com Privacy Policy