Search Icon

SAP Security Notes Review: June 2025

10 June 2025

banner image

Overview

SAP’s security patch day for June 2025 has seen the release of 14 OSS SAP security notes. One note has been classified as critical, Five as high, six as medium, and two  as low based on CVSS v3.0 Rating.

June 2025: Security Notes by CVSS v3 Base Score

Four notes have been released for:

  • SAP S/4HANA

Single notes have been released for:

  • SAP NetWeaver Application Server for ABAP
  • SAP GRC
  • SAP Business Warehouse and SAP Plug-In Basis
  • SAP BusinessObjects Business Intelligence
  • SAP NetWeaver Visual Composer
  • SAP MDM Server
  • SAP NetWeaver
  • SAP Business One Integration Framework
  • SAP Business Objects Business Intelligence Platform
  • SAPUI5 applications

Security Notes June Product Category

Vulnerabilities: June 2025 Highlights

[CVE-2025-42983] Missing Authorisation check in SAP Business Warehouse and SAP Plug-In Basis (SAP Note 3606484)

SAP Business Warehouse and SAP Plug-In Basis allow an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in data loss or rendering the system unusable. Upon successful exploitation, an attacker can completely delete database entries but is unable to read any data.

[CVE-2025-42990] HTML Injection in Unprotected SAPUI5 applications (SAP Note 3601169)

Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, with the goal of redirecting users to the attacker-controlled URL. This issue could impact the integrity of the application. 

About this Review

On the second Tuesday of each month, SAP release security updates to their software products. At Applexus, we analyse all of the released security updates and produce this security review, including sending bespoke recommendations for each of our managed service customers.

There is more information on how we handle SAP security updates, including information on SAP’s process, the CVE process and the CVSS base scores in our earlier article on addressing security vulnerabilities in SAP software.

Related Blogs

AI-First SAP SuccessFactors AMS Blog Banner Image

01 September 2026

Reimagining SuccessFactors Support: From Tickets to Intelligence: An AI-First AMS Model

SAP SuccessFactors Agentic AI: Joule and AI Agents

24 August 2026

SAP SuccessFactors - From Systems of Record to Systems of Intelligence

Pricefx blog banner

21 August 2026

"We Already Have a CRM." Why That Isn't a Pricing Strategy.

Leveraging claude in sap successfactors

17 August 2026

Leveraging claude in sap successfactors

AI-embedded SAP Blog banner

29 July 2026

AI Built In, Not Bolted On: What AI-Embedded AMS Actually Looks Like

Rethinking blog banner

28 July 2026

Rethinking Application Managed Services for HR Shared Services

successfactor blog banner

22 July 2026

Is Your SAP SuccessFactors Environment Ready for SAP Business AI and Joule?

Pricefx Certified

13 July 2026

Beyond the Platform: Why Certified Pricefx Experts Make the Difference