Enhance Your SAP Security with Vicxer! Discover how to safeguard your SAP environment effectively.

SAP Security Patch Day – January 2025

On January 14, 2025, SAP released 14 new Security Notes as part of its monthly Security Patch Day.

This release affects various SAP products, containing important vulnerabilities classified as Critical and High severity, indicating the possible risks at which the affected SAP products are exposed, if the vulnerabilities are not properly mitigated

What you need to know

  • These notes address a wide array of components, including SAP NetWeaver AS for ABAP/JAVA, SAP BusinessObjects Business Intelligence Platform, SAP GUI for Windows/Java, SAPSetup, and SAP Business Workflow. 
  • Vulnerabilities span Critical, High, Medium, and Low severity levels, with two Critical notes (CVSS 9.9), four High (CVSS ranging from 7.8 to 8.8), seven Medium (CVSS 4.3 to 6.5), and one Low (CVSS 2.2) . 
  • Unlike December’s release, no updates to previously released notes were announced. 

This month’s security notes overview

1) Critical Vulnerabilities (CVSS 9.9)

 

  • [CVE-2025-0070] Improper Authentication (Note #3537476): A privilege escalation vulnerability in SAP NetWeaver ABAP Server and ABAP Platform. 
  • [CVE-2025-0066] Information Disclosure (Note #3550708): A critical flaw in the Internet Communication Framework of SAP NetWeaver for ABAP and ABAP Platform that can expose sensitive data. 

2) High Priority (CVSS 7.8 – 8.8) 

  • [CVE-2025-0063] SQL Injection (Note #3550816): Impacts SAP NetWeaver AS for ABAP and ABAP Platform, allowing attackers to compromise confidentiality, integrity, and availability of critical databases. 
  • [CVE-2025-0061 & -0060] Multiple Vulnerabilities (Note #3474398): Affect SAP BusinessObjects Business Intelligence Platform. Includes information disclosure and code injection. 
  • [CVE-2025-0069] DLL Hijacking (Note #3542533): Found in SAPSetup, enabling privilege escalation on Windows hosts. 

3) Medium Priority (CVSS 4.3 – 6.5) 

Multiple missing authorization checks, information disclosure, and cross-site scripting. Key examples include: 

  • [CVE-2025-0058] Information Disclosure (Note #3542698) in SAP Workflow and Flexible Workflow. 
  • [CVE-2025-0067] Missing Authorization Check (Note #3540108) in SAP NetWeaver AS Java. 
  • [CVE-2025-0053] Information Disclosure (Note #3536461) in SAP NetWeaver AS for ABAP. 

4) Low Priority (CVSS 2.2) 

  • Multiple Buffer Overflow (Note #3492169): Impacting SAP BusinessObjects BI Platform (Crystal Reports for Enterprise). Despite the low severity, it could lead to denial-of-service conditions if left unpatched. 

Key Affected SAP Components

  • SAP NetWeaver AS (ABAP & Java): Several notes are centered around missing authorization checks, SQL injection, and kernel issues.
  • SAP GUI (Windows/Java/HTML): Patches Enhance local stored information, in order to prevent data exposure. 
  • SAP BusinessObjects BI Platform: Multiple vulnerabilities, including code injection and session hijacking, which can compromise confidentiality and integrity. 
  • SAP Business Workflow & Flexible Workflow: Information disclosure in attachments if not properly restricted. 
  • SAPSetup: DLL hijacking vulnerability potentially enabling privilege escalation in Windows environments. 

The Bottom Line

  • The January 2025 SAP Security Patch Day underscores the critical need for timely application of patches, particularly for the Critical and High severity issues that enable remote exploits, privilege escalation, or compromise of sensitive data. Delaying patches exposes SAP landscapes to substantial risk.
  • At Vicxer, our team of SAP security specialists is here to help organizations navigate these critical updates and manage the patching process end-to-end.
  • Vicxer’s SAP Security Platform helps you handle the complete security lifecycle—from vulnerability discovery in your SAP landscape to remediation and 24/7 monitoring—to ensure a robust defense against evolving threats. 

Table of Contents

Discover more from Vicxer Inc | SAP Security

Subscribe now to keep reading and get access to the full archive.

Continue reading