What you need to know
On June 10, 2025, SAP released 14 new Security Notes as part of its monthly Security Patch Day. This month’s release addresses a range of vulnerabilities across various SAP products, with 1 Critical-severity vulnerability (CVSS 9.6), 5 High-severity issues (CVSS 7.5–8.8), 6 Medium-severity vulnerabilities (CVSS 4.3–6.7), and 2 Low-severity issues (CVSS 3.0–3.7). The focus remains on authorization bypasses and information disclosure risks, with significant impacts on core components like SAP NetWeaver and Business Intelligence platforms.
Key Highlights by Severity
Critical Priority (CVSS 9.6):
- A critical missing authorization check in a core SAP NetWeaver component allows authenticated attackers to escalate privileges, posing a severe risk to system integrity and availability with a CVSS score of 9.6. This vulnerability demands immediate attention due to its potential for widespread impact in production environments.
High Priority (CVSS 7.5 – 8.8):
- Information disclosure in SAP GRC (AC Plugin) with a CVSS of 8.8, enabling attackers to access sensitive data and compromise system integrity.
- Missing authorization checks in SAP Business Warehouse and Plug-In Basis (CVSS 8.5), which could disrupt operations by allowing unauthorized actions.
- Cross-Site Scripting (XSS) in SAP BusinessObjects BI Workspace (CVSS 8.2), risking session information exposure.
- Directory Traversal in SAP NetWeaver Visual Composer (CVSS 7.6), allowing high-privileged users to access or modify files.
- Multiple vulnerabilities in SAP MDM Server (CVSS 7.5), including memory corruption issues that could impact system availability
Medium Priority (CVSS 4.3 – 6.7):
- Several missing authorization checks in SAP S/4HANA applications, affecting components like Enterprise Event Enablement and Bank Account Management, with CVSS scores ranging from 4.3 to 6.7.
- XSS vulnerabilities in SAP NetWeaver ABAP Keyword Documentation (CVSS 5.8) and security misconfigurations in SAP Business One Integration Framework (CVSS 5.3), posing limited but notable risks.
Low Priority (CVSS 3.0 – 3.7):
- Issues such as Server-Side Request Forgery in SAP BusinessObjects BI Platform (CVSS 3.7) and HTML Injection in unprotected SAPUI5 applications (CVSS 3.0), with minimal impact on system integrity or availability.
Main Affected SAP Components
- SAP NetWeaver (Application Server for ABAP and Visual Composer): Continues to be a primary target, with critical and high-severity vulnerabilities affecting core functionalities and development environments.
- SAP BusinessObjects BI Platform: High and low-severity issues in BI Workspace and related components, focusing on XSS and information disclosure risks.
- SAP S/4HANA: Multiple medium-severity authorization issues across various applications, including financial and procurement modules.
- SAP GRC (AC Plugin): High-severity information disclosure risks that could lead to privilege escalation.
- SAP MDM Server: High-severity vulnerabilities targeting memory corruption and session management, a less frequent but significant concern.
Notable Trends
- Authorization Issues Persist: Over 35% of the vulnerabilities involve missing authorization checks, a recurring theme that underscores ongoing challenges in access control implementation across SAP landscapes.
- Continued Targeting of Visual Composer: Following critical issues in May, SAP NetWeaver Visual Composer faces a new high-severity Directory Traversal vulnerability, indicating active exploitation research by threat actors.
- No Direct Updates to Prior Fixes: Unlike the previous month, June’s notes are primarily new vulnerabilities, though some build on known attack vectors in components like Visual Composer.
- Diverse Attack Vectors: The range of issues spans XSS, information disclosure, directory traversal, and memory corruption, highlighting the need for comprehensive security strategies beyond patching.
The Bottom Line:
June’s release emphasizes persistent risks in SAP NetWeaver and related core components, necessitating urgent action:
- Prioritize Critical Patch for the NetWeaver authorization flaw to prevent privilege escalation and system disruption.
- Address High-Severity Issues in GRC, Business Warehouse, and BI Platform to mitigate data exposure and operational risks.
- Enhance Monitoring for Visual Composer, given the ongoing development of new attack vectors targeting this component.
- Audit Authorization Configurations across S/4HANA and other affected modules to close privilege escalation gaps.
This month’s patches reflect the evolving threat landscape, with attackers focusing on both legacy components and critical infrastructure. Organizations must prioritize rapid patching while adopting proactive measures like enhanced monitoring and zero-trust architectures to minimize exposure.