HomeUpdatesSAP: Patch Day notes – Fixing critical vulnerabilities

SAP: Patch Day notes – Fixing critical vulnerabilities

As part of scheduled security maintenance, SAP released the Patch Day notes September 2025, addressing a total of 21 new vulnerabilities and providing updates for four previous security advisories.

SAP: Patch Day notes vulnerabilities

Some of the most important fixes this month include four critical vulnerabilities that could expose SAP systems to significant risk: remote code execution and complete system compromise. Organizations are urged to apply these updates immediately to protect their operational environments.

See also: 45 domains reveal long-term cyberespionage by Salt Typhoon

SAP: Vulnerability Fix

This month's most severe vulnerability, identified as CVE-2025-42944, has a CVSS score of 10.0/10, the maximum possible. It is an "Insecure Deserialization vulnerability" in the Remote Method Invocation (RMI-P4) component of SAP NetWeaver. A successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code, potentially leading to a complete breach of the confidentiality, integrity, and availability of the affected system.

Another critical issue, CVE-2025-42922, affects SAP NetWeaver Application Server (AS) Java. This vulnerability, with a CVSS score of 9.9, allows a low-privilege attacker to perform unauthorized file operations. This could allow the attacker to read, modify, or delete sensitive system files.

An update has also been released for a previously known critical vulnerability, CVE-2023-27500, in SAP NetWeaver AS for ABAP and ABAP Platform. With a CVSS score of 9.6, this vulnerability could be exploited by a low-privileged attacker to overwrite critical system, potentially causing system disruption and data corruption.

See also: 18 popular code packages hacked for crypto theft

SAP: Patch Day notes – Fixing critical vulnerabilities

The fourth critical vulnerability, CVE-2025-42958, is also found in SAP NetWeaver and has a CVSS score of 9.1. This vulnerability could be exploited by an attacker with high privileges to bypass authentication mechanisms and gain unauthorized access to critical functions and data.

In addition to the critical issues, SAP fixed several high-priority vulnerabilities. These include:

– CVE-2025-42933: A vulnerability in SAP Business One (SLD) with a CVSS score of 8.8.
– CVE-2025-42929: A vulnerability in SAP Landscape Transformation Replication Server, with a CVSS score of 8.1.
– CVE-2025-42916: A vulnerability in SAP S/4HANA, also with a CVSS score of 8.1.
– An update for CVE-2025-27428, in SAP NetWeaver and ABAP Platform, with a CVSS score of 7.7.

The remaining updates address medium and low severity, such as: Cross-Site Scripting (XSS), Denial of Service (DoS), and Lack of Authorization Checks in a range of products.

See also: Vulnerability in Progress OpenEdge allows code execution

SAP: Patch Day notes – Fixing critical vulnerabilities

Of the 25 security notes released in September 2025 Patch Day notes , 21 were new. SAP administrators are advised to review the overall list of security notes and prioritize the application of updates:

SAP Note #CVE IDVulnerability TitleAffected ProductPriorityCVSS 3.0 Score
3634501CVE-2025-42944Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)SAP Netweaver (RMI-P4)Critical10.0
3643865CVE-2025-42922Insecure File Operations vulnerability in SAP NetWeaver AS Java (Deploy Web Service)SAP NetWeaver AS Java (Deploy Web Service)Critical9.9
3627373CVE-2025-42958Missing Authentication check in SAP NetWeaverSAP NetWeaverCritical9.1
3642961CVE-2025-42933Insecure Storage of Sensitive Information in SAP Business One (SLD)SAP Business One (SLD)High8.8
3633002CVE-2025-42929Missing input validation vulnerability in SAP Landscape Transformation Replication ServerSAP Landscape Transformation Replication ServerHigh8.1
3635475CVE-2025-42916Missing input validation vulnerability in SAP S/4HANA (Private Cloud or On-Premise)SAP S/4HANA (Private Cloud or On-Premise)High8.1
3620264CVE-2025-22228Security Misconfiguration vulnerability in Spring security within SAP Commerce Cloud and SAP DatahubSAP Commerce Cloud and SAP DatahubMedium6.6
3614067CVE-2025-42930Denial of Service (DoS) vulnerability in SAP Business Planning and ConsolidationSAR Business Planning and ConsolidationMedium6.5
3635587CVE-2025-42912, CVE-2025-42913, CVE-2025-42914Missing Authorization check in SAP HCM (My Timesheet Fiori 2.0 application)SAR HCM (My Timesheet Fiori 2.0 application)Medium6.5
3643832CVE-2025-42917Missing Authorization check in SAP HCM (Approve Timesheets Fiori 2.0 application)SAP HCM (Approve Timesheets Fiori 2.0 application)Medium6.5
3611420CVE-2023-5072Denial of Service (DoS) vulnerability due to outdated JSON library used in SAP BusinessObjects Business Intelligence PlatformSAP BusinessObjects Business Intelligence PlatformMedium6.5
3647098CVE-2025-42920Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship ManagementSAP Supplier Relationship ManagementMedium6.1
3629325CVE-2025-42938Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP PlatformSAP NetWeaver ABAP PlatformMedium6.1
3409013CVE-2025-42915Missing Authorization Check in Fiori app (Manage Payment Blocks)Fiori app (Manage Payment Blocks)Medium5.4
3619465CVE-2025-42926Missing Authentication check in SAP NetWeaver Application Server JavaSAP NetWeaver Application Server JavaMedium5.3
3627644CVE-2025-42911Missing Authorization check in SAP NetWeaver (Service Data Download)SAR NetWeaver (Service Data Download)Medium5.0
3640477CVE-2025-42925Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)SAP NetWeaver AS Java (IIOP Service)Medium4.3
3450692CVE-2025-42923Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App (F4044 Manage Work Center Groups)SAP Fiori App (F4044 Manage Work Center Groups)Medium4.3
3623504CVE-2025-42918Missing Authorization check in SAP NetWeaver Application Server for ABAP (Background Processing)SAP NetWeaver Application Server for ABAP (Background Processing)Medium4.3
3525295CVE-2025-42927Information Disclosure due to Outdated OpenSSL Version in SAP NetWeaver AS Java (Adobe Document Service)SAP NetWeaver AS Java (Adobe Document Service)Low3.4
3632154CVE-2024-13009Potential Improper Resource Release vulnerability in SAP Commerce CloudSAP Commerce CloudLow3.1
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS