SAP Security Patch Day September 2025


As part of its scheduled security maintenance, SAP released its September 2025 Patch Day notes, addressing a total of 21 new vulnerabilities and providing updates to four previously released security advisories.

Among the newly addressed flaws are four critical vulnerabilities that could expose SAP systems to significant risk, including remote code execution and complete system compromise.

Organizations are strongly urged to apply these patches to safeguard their enterprise environments.

Google News

Critical Vulnerabilities Patched

This month’s most severe vulnerability, identified as CVE-2025-42944, carries a CVSS score of 10.0, the highest possible rating.

This flaw is an Insecure Deserialization vulnerability in SAP NetWeaver’s Remote Method Invocation (RMI-P4) component.

A successful exploit could allow an unauthenticated remote attacker to execute arbitrary code, potentially leading to a full compromise of the affected system’s confidentiality, integrity, and availability.

Another critical issue, CVE-2025-42922, affects the SAP NetWeaver Application Server (AS) Java. This Insecure File Operations vulnerability, with a CVSS score of 9.9, allows a low-privileged attacker to perform unauthorized file operations.

This could enable the attacker to read, modify, or delete sensitive system files, leading to a significant impact on the system’s security.

An update was issued for a previously disclosed critical vulnerability, CVE-2023-27500, a Directory Traversal flaw in SAP NetWeaver AS for ABAP and ABAP Platform.

With a CVSS score of 9.6, this vulnerability could be exploited by an attacker with low privileges to overwrite critical system files, potentially causing system-wide disruption and data corruption.

The fourth critical vulnerability, CVE-2025-42958, is a Missing Authentication check in SAP NetWeaver, rated with a CVSS score of 9.1.

This vulnerability could be exploited by a highly privileged attacker to bypass authentication mechanisms, granting them unauthorized access to critical functionalities and data.

High-Priority Flaws And Other Patches

In addition to the critical issues, SAP patched several high-priority vulnerabilities. These include:

  • CVE-2025-42933: An Insecure Storage of Sensitive Information flaw in SAP Business One (SLD) with a CVSS score of 8.8.
  • CVE-2025-42929: A Missing Input Validation vulnerability in SAP Landscape Transformation Replication Server, rated 8.1.
  • CVE-2025-42916: A similar Missing Input Validation flaw in SAP S/4HANA, also with a CVSS of 8.1.
  • An update to CVE-2025-27428, a Directory Traversal vulnerability in SAP NetWeaver and ABAP Platform, carrying a CVSS score of 7.7.

The remaining patches address vulnerabilities of medium and low severity, including Cross-Site Scripting (XSS), Denial of Service (DoS), and Missing Authorization checks across a range of SAP products such as SAP Commerce Cloud, SAP BusinessObjects, and several Fiori applications.

Of the 25 security notes released on SAP’s September 2025 Patch Day, 21 were new. Here is a table detailing these vulnerabilities:

SAP Note #CVE IDVulnerability TitleAffected ProductPriorityCVSS 3.0 Score
3634501CVE-2025-42944Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)SAP Netweaver (RMI-P4)Critical10.0
3643865CVE-2025-42922Insecure File Operations vulnerability in SAP NetWeaver AS Java (Deploy Web Service)SAP NetWeaver AS Java (Deploy Web Service)Critical9.9
3627373CVE-2025-42958Missing Authentication check in SAP NetWeaverSAP NetWeaverCritical9.1
3642961CVE-2025-42933Insecure Storage of Sensitive Information in SAP Business One (SLD)SAP Business One (SLD)High8.8
3633002CVE-2025-42929Missing input validation vulnerability in SAP Landscape Transformation Replication ServerSAP Landscape Transformation Replication ServerHigh8.1
3635475CVE-2025-42916Missing input validation vulnerability in SAP S/4HANA (Private Cloud or On-Premise)SAP S/4HANA (Private Cloud or On-Premise)High8.1
3620264CVE-2025-22228Security Misconfiguration vulnerability in Spring security within SAP Commerce Cloud and SAP DatahubSAP Commerce Cloud and SAP DatahubMedium6.6
3614067CVE-2025-42930Denial of Service (DoS) vulnerability in SAP Business Planning and ConsolidationSAP Business Planning and ConsolidationMedium6.5
3635587CVE-2025-42912, CVE-2025-42913, CVE-2025-42914Missing Authorization check in SAP HCM (My Timesheet Fiori 2.0 application)SAP HCM (My Timesheet Fiori 2.0 application)Medium6.5
3643832CVE-2025-42917Missing Authorization check in SAP HCM (Approve Timesheets Fiori 2.0 application)SAP HCM (Approve Timesheets Fiori 2.0 application)Medium6.5
3611420CVE-2023-5072Denial of Service (DoS) vulnerability due to outdated JSON library used in SAP BusinessObjects Business Intelligence PlatformSAP BusinessObjects Business Intelligence PlatformMedium6.5
3647098CVE-2025-42920Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship ManagementSAP Supplier Relationship ManagementMedium6.1
3629325CVE-2025-42938Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP PlatformSAP NetWeaver ABAP PlatformMedium6.1
3409013CVE-2025-42915Missing Authorization Check in Fiori app (Manage Payment Blocks)Fiori app (Manage Payment Blocks)Medium5.4
3619465CVE-2025-42926Missing Authentication check in SAP NetWeaver Application Server JavaSAP NetWeaver Application Server JavaMedium5.3
3627644CVE-2025-42911Missing Authorization check in SAP NetWeaver (Service Data Download)SAP NetWeaver (Service Data Download)Medium5.0
3640477CVE-2025-42925Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)SAP NetWeaver AS Java (IIOP Service)Medium4.3
3450692CVE-2025-42923Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App (F4044 Manage Work Center Groups)SAP Fiori App (F4044 Manage Work Center Groups)Medium4.3
3623504CVE-2025-42918Missing Authorization check in SAP NetWeaver Application Server for ABAP (Background Processing)SAP NetWeaver Application Server for ABAP (Background Processing)Medium4.3
3525295CVE-2025-42927Information Disclosure due to Outdated OpenSSL Version in SAP NetWeaver AS Java (Adobe Document Service)SAP NetWeaver AS Java (Adobe Document Service)Low3.4
3632154CVE-2024-13009Potential Improper Resource Release vulnerability in SAP Commerce CloudSAP Commerce CloudLow3.1

SAP administrators are advised to review the complete list of security notes and prioritize the application of patches, starting with the critical vulnerabilities, to protect their systems from potential exploitation.

Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.



Source link