SAP Security Notes Review: May 2025
13 May 2025

Overview
SAP’s security patch day for May 2025 has seen the release of 18 OSS SAP security notes. Two notes have been classified as critical, five as high, and eleven as medium based on the CVSS v3.0 Rating.

Two notes have been released for:
- SAP NetWeaver
- SAP Service Parts Management
- SAP Supplier Relationship Management
Single notes have been released for:
- SAP S/4HANA Cloud Private Edition or on Premise
- SAP Business Objects Business Intelligence Platform
- SAP Landscape Transformation
- SAP PDCE
- SAP Gateway Client
- SAP S/4HANA (Private Cloud & On-Premise)
- SAP NetWeaver Application Server ABAP and ABAP Platform
- SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal
- SAP Digital Manufacturing
- SAP Data Services Management Console
- SAP S4/HANA (OData meta-data property)
- SAP GUI for Windows

Vulnerabilities: May 2025 Highlights
[CVE-2024-39592] Missing Authorisation check in SAP PDCE (SAP Note 3483344)
Elements of PDCE do not perform necessary authorisation checks for an authenticated user, resulting in the escalation of privileges.
This allows an attacker to read sensitive information, causing high impact on the confidentiality of the application.
[CVE-2025-31329] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform (SAP Note 3577287)
SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed by the victim, sensitive information such as user credentials is exposed. These credentials may then be used to gain unauthorised access to local or adjacent systems. This results in high impact to Confidentiality, with no significant effect on Integrity or Availability.







