Search Icon

SAP Security Notes Review: January 2025

14 January 2025

banner image

Overview

SAP’s security patch day for January 2025 has seen the release of 14 OSS SAP security notes. Two notes have been classified as critical, three as high, eight as medium, and one as low based on CVSS v3.0 Rating.

Sec Notes CVSS v3 Scores January 2025

Two notes have been released for:

  • SAP NetWeaver Application Server for ABAP and ABAP Platform

Single notes have been released for:

  • SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework)
  • SAP BusinessObjects Business Intelligence Platform
  • SAPSetup
  • SAP Business Workflow and SAP Flexible Workflow
  • SAP NetWeaver Application Server Java
  • SAP GUI for Windows
  • SAP GUI for Java
  • SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML)
  • SAP NetWeaver AS JAVA (User Admin Application)
  • SAP NetWeaver Application Server ABAP
  • SAP BusinessObjects Business Intelligence Platform (Crystal Reports for Enterprise)

Sec Notes Product Categories January 2025

Vulnerabilities: January 2025 Highlights

[CVE-2025-0070] Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform (SAP Note 3537476)

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential security concerns. This results in a high impact on confidentiality, integrity, and availability.

[CVE-2025-0066] Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) (SAP Note 3550708)

Under certain conditions, SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows attackers to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an application.

[CVE-2025-0063] SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform (SAP Note 3550816)

SAP NetWeaver AS ABAP and ABAP Platform does not check for authorisation when a user executes some RFC function modules. This could lead to an attacker with basic user privileges to gain control over the data in Informix database, leading to complete compromise of confidentiality, integrity, and availability.

About this Review

On the second Tuesday of each month, SAP release security updates to their software products. At Absoft, we analyse all of the released security updates and produce this security review, including sending bespoke recommendations for each of our managed service customers.

There is more information on how we handle SAP security updates, including information on SAP’s process, the CVE process and the CVSS base scores in our earlier article on addressing security vulnerabilities in SAP software.

Related Blogs

Modern ERP system streamlining fashion and retail operations across channels

10 November 2025

Why Modern ERP is No Longer Optional for Fashion & Retail Success

Clean core blog banner

18 June 2025

Why Clean Core for your Journey to RISE and AI

A group of round wooden circles with black people icons

16 May 2025

Roles and Authorization – The Often-Neglected Aspect of a S/4HANA Migration Journey

Celerite Assessment Webinar for S/4Hana Migration

25 April 2025

Why the Right Assessment is Key to a Successful S/4HANA Migration

applexus-runway-approach-blog-banner

21 November 2024

Runway Approach: Revolutionizing Your S/4HANA Journey

Team working on laptops in a modern office with digital cloud icons overlayed, symbolizing collaboration, cloud analytics, and predictive insights in SAP Analytics Cloud.

01 November 2024

Importance of Predictive Analytics in SAC for Business

celerites-innovative-approach-for-afs-to-s4-fashion_banner

06 August 2024

Beyond Greenfield: CeleRITE’s Innovative Approach for AFS to S/4 Fashion

05 June 2024

What is the SAP Kernel, and Should I Care?