{"id":13015,"date":"2025-03-19T10:53:14","date_gmt":"2025-03-19T08:53:14","guid":{"rendered":"https:\/\/www.inprosec.com\/?p=13015"},"modified":"2025-03-19T10:53:14","modified_gmt":"2025-03-19T08:53:14","slug":"sap-security-notes-march-2025","status":"publish","type":"post","link":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/","title":{"rendered":"SAP Security Notes, March 2025"},"content":{"rendered":"<p><strong>Inprosec through its services, such as the SAP Security Assessment, helps its customers to improve the security levels of their SAP systems.<\/strong><\/p>\n\n<h2>March 2025 Notes<\/h2>\n<h3>Summary and Highlights of the Month<\/h3>\n<div>\n<div class=\"elementToProof\">Este mes el n\u00famero total de notas ha sido de 25, 4 m\u00e1s que en el periodo anterior. Este mes no ha habido HotNews, igual que en el periodo anterior. En cuanto al n\u00famero de notas de criticidad alta, estas se han reducido en 1\u00a0con respecto al mes anterior, pasando de 6\u00a0a 5. Las notas medias y bajas no ser\u00e1n revisadas, por lo que <b>daremos detalle de un total de 5\u00a0notas<\/b>\u00a0(todas las que tengan un CVSS de <b>7 <\/b>o mayor).<\/div>\n<p>Tenemos <b>un<\/b>\u00a0<b>total de 25 notas <\/b>para todo el mes (22 nuevas y 3 actualizaciones de notas publicadas en meses anteriores).<\/p>\n<p>Revisaremos en detalle un total de 5 notas, todas de criticidad alta:<\/p>\n<ol start=\"1\">\n<li>\n<div><b>La nota m\u00e1s cr\u00edtica del mes (CVSS <\/b> <span style=\"color: #ff0000;\"><b>8,8<\/b><\/span><b>) <\/b>es una High, se trata de una nota relacionada con <b>\u201c<\/b><b>Cross-Site Scripting (XSS) vulnerability in SAP Commerce (Swagger UI)<\/b><b>\u201d.<\/b><\/div>\n<\/li>\n<li>\n<div>La siguiente en criticidad, con la misma valoracion que la primera<b>\u00a0(CVSS<\/b>\u00a0<span style=\"color: #ff0000;\"><b>8,8<\/b><\/span><b>)<\/b>\u00a0se trata de una nota relacionada con <b>\u201c<\/b><b>Missing Authorization check in SAP NetWeaver (ABAP Class Builder)<\/b><b>\u201d.<\/b><\/div>\n<\/li>\n<li>\n<div>La siguiente en criticidad<b>\u00a0(CVSS<\/b>\u00a0<span style=\"color: #ff0000;\"><b>8,6<\/b><\/span><b>)<\/b>\u00a0se trata de una nota relacionada con <b>\u201c<\/b><b>Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud<\/b><b>\u201d.<\/b><\/div>\n<\/li>\n<li>\n<div>Este mes el tipo m\u00e1s predominante est\u00e1 relacionado con <b>\u201c<\/b><b>Missing Authorization check<\/b><b>\u201d<\/b>\u00a0(8\/25 en patch day).<\/div>\n<\/li>\n<\/ol>\n<p>En la gr\u00e1fica podemos ver la <b><u>clasificaci\u00f3n de las notas de marzo<\/u><\/b>, adem\u00e1s de la evoluci\u00f3n y clasificaci\u00f3n de los \u00faltimos 5 meses anteriores (solo las notas del Sec. Tuesday \/ Patch Day \u2013 by SAP):<\/p>\n<\/div>\n<p><img decoding=\"async\" class=\"aligncenter  wp-image-13017\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/03\/notas-sap-marzo-2025.jpg\" alt=\"\" width=\"780\" height=\"410\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/03\/notas-sap-marzo-2025.jpg 1200w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/03\/notas-sap-marzo-2025-300x158.jpg 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/03\/notas-sap-marzo-2025-1024x538.jpg 1024w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/03\/notas-sap-marzo-2025-600x315.jpg 600w\" sizes=\"(max-width: 780px) 100vw, 780px\" \/><\/p>\n<h3>Full details<\/h3>\n<p>The <strong>complete detail of the most relevant notes<\/strong> is as follows:<\/p>\n<ol>\n<li>\n<div><b><u>Cross-Site Scripting (XSS) vulnerability in SAP Commerce (Swagger UI) (<\/u><\/b><b><a id=\"OWAe926d963-a1e2-162b-9b4c-9600b106c8d4\" class=\"x_x_x_x_x_OWAAutoLink x_x_x_x_x_elementToProof\" title=\"https:\/\/me.sap.com\/notes\/3569602\" href=\"https:\/\/me.sap.com\/notes\/3569602\" data-auth=\"NotApplicable\" data-linkindex=\"0\">3569602<\/a><\/b><b><u>)<\/u>:<\/b>\u00a0Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged by an attacker to execute a cross-site scripting (XSS) attack. This could lead to a high impact on the confidentiality, integrity, and availability of data in SAP Commerce. It is important to note that other components of SAP Commerce are not affected and significant user interaction is required for this to materialize. Switching starter themes eliminates the risk of this attack by removing the explore feature of Swagger UI which was vulnerable to the DOM-based XSS attack. The vulnerable DOM element is no longer rendered on Swagger UI. There is a Work around. <b>CVSS v3\u00a0Base Score <\/b><span style=\"color: #ff0000;\"><b>8,8<\/b><\/span><b>\/ 10 [<\/b><b><a id=\"OWAf19c035c-5cfa-8550-daa5-f8b2773641f7\" class=\"x_x_OWAAutoLink x_x_elementToProof\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-27434\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-27434\" data-auth=\"NotApplicable\" data-linkindex=\"1\">CVE-2025-27434<\/a><\/b><b>]<\/b><\/div>\n<\/li>\n<li>\n<div><b><u>Missing Authorization check in SAP NetWeaver (ABAP Class Builder)\u00a0(<\/u><\/b><b><a id=\"OWAf5302667-2d35-d399-3379-b27b07e4338c\" class=\"x_x_x_x_x_OWAAutoLink x_x_x_x_x_elementToProof\" title=\"https:\/\/me.sap.com\/notes\/3563927\" href=\"https:\/\/me.sap.com\/notes\/3563927\" data-auth=\"NotApplicable\" data-linkindex=\"2\">3563927<\/a><\/b><b><u>)<\/u>:<\/b>\u00a0Due to missing authorization check, SAP NetWeaver\u00a0(ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in escalation of privileges. On successful exploitation, this could result in disclosure of highly sensitive information. It could also have a high impact on the integrity and availability of the application. By this correction functionality restricted to the ABAP Development, workbench is excluded from execution by transaction SA38. There isn&#8217;t a workaround <b>CVSS v3\u00a0Base Score <\/b><span style=\"color: #ff0000;\"><b>8,8<\/b><\/span><b>\/ 10 [<\/b><b><a id=\"OWA0c3a6be7-72c8-e18f-e58e-1e177e36c71e\" class=\"x_x_OWAAutoLink x_x_elementToProof\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-26661\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-26661\" data-auth=\"NotApplicable\" data-linkindex=\"3\">CVE-2025-26661<\/a><\/b><b>]\u00a0<\/b><\/div>\n<\/li>\n<li>\n<div>\u00a0<b><u>Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud\u00a0(<\/u><\/b><b><a id=\"OWAdce48f70-041e-d05c-6bdf-fed4b9787e96\" class=\"x_x_x_x_x_OWAAutoLink x_x_x_x_x_elementToProof\" title=\"https:\/\/me.sap.com\/notes\/3566851\" href=\"https:\/\/me.sap.com\/notes\/3566851\" data-auth=\"NotApplicable\" data-linkindex=\"4\">3566851<\/a><\/b><b><u>)<\/u>:<\/b>\u00a0SAP Commerce Cloud\u00a0uses a version of Apache Tomcat that could be vulnerable to DOS (CVE-2024-38286) and unchecked error conditions (CVE-2024-52316). For these vulnerabilities, prerequisites must apply first, as elaborated in the CVEs. To fix this vulnerability you have to update Apache Tomcat to versions not vulnerable to these CVEs. <b>CVSS v3\u00a0Base Score <\/b><span style=\"color: #ff0000;\"><b>8,6<\/b><\/span><b>\/ 10 [<\/b><b><a id=\"OWA4db44d20-ea83-c69d-fbeb-928befb7a923\" class=\"x_x_OWAAutoLink x_x_elementToProof\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-38286\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-38286\" data-auth=\"NotApplicable\" data-linkindex=\"5\">CVE-2024-38286<\/a><\/b><b>]\u00a0<\/b><\/div>\n<div><b>\u00a0<\/b><\/div>\n<\/li>\n<li>\n<div>\u00a0<b><u>Update &#8211; Authentication bypass via authorization code injection in SAP Approuter\u00a0(<\/u><\/b><b><a id=\"OWAfedf51fc-aae4-73e6-173c-3ae21548bcd9\" class=\"x_x_x_x_x_x_x_OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3567974\" href=\"https:\/\/me.sap.com\/notes\/3567974\" data-auth=\"NotApplicable\" data-linkindex=\"6\">3567974<\/a><\/b><b><u>)<\/u>: <\/b>\u00a0The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the application. To fix the error, please upgrade to SAP Approuter node.js package to 16.7.2 or higher. This fix ensures that the url protocol in the login callback url is a valid one.<b>\u00a0<\/b><b>CVSS v3\u00a0Base Score <\/b><span style=\"color: #ff0000;\"><b>8,1<\/b><\/span><b>\/ 10 [<\/b><b><a id=\"OWAaafd4aa5-617b-6fb0-8cc9-c8c1cb9954ef\" class=\"x_x_x_x_x_x_x_OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-24876\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-24876\" data-auth=\"NotApplicable\" data-linkindex=\"7\">CVE-2025-24876<\/a><\/b><b>]\u00a0<\/b><\/div>\n<\/li>\n<li>\n<div><b><u>Update &#8211;\u00a0Missing Authorization check in SAP PDCE\u00a0(<\/u><\/b><b><a id=\"OWAb668304f-712f-77f2-264e-674731904094\" class=\"x_x_x_x_x_OWAAutoLink x_x_x_x_x_elementToProof\" title=\"https:\/\/me.sap.com\/notes\/3483344\" href=\"https:\/\/me.sap.com\/notes\/3483344\" data-auth=\"NotApplicable\" data-linkindex=\"8\">3483344<\/a><\/b><b><u>)<\/u>: <\/b>Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive information causing high impact on the confidentiality of the application. When this note is aplied, the affected functions have now been <b>deactivated<\/b>\u00a0to restrict accesses. <b>CVSS v3\u00a0Base Score <\/b><span style=\"color: #ffcc00;\"><b>7,6<\/b><\/span><b>\/ 10 [<\/b><b><a id=\"OWA1a4444dd-bdf9-3b49-da9c-30d5efd40837\" class=\"x_x_OWAAutoLink x_x_elementToProof\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-39592\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-39592\" data-auth=\"NotApplicable\" data-linkindex=\"9\">CVE-2024-39592<\/a><\/b><b>]<\/b><\/div>\n<\/li>\n<\/ol>\n<h3 style=\"font-weight: 400;\"><strong>Reference links<\/strong><\/h3>\n<p>Other references, from SAP and Onapsis (march):<\/p>\n<p><b><a id=\"OWAe8527265-9181-ce8b-e860-c86720c8f4e9\" class=\"x_x_OWAAutoLink\" title=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/march-2025.html\" href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/march-2025.html\" data-auth=\"NotApplicable\" data-linkindex=\"10\">SAP Security Patch Day &#8211; March 2025<\/a><\/b><\/p>\n<p><b><a id=\"OWA7bf321b1-5ba9-fd94-d814-8e941c4216a7\" class=\"x_x_OWAAutoLink\" title=\"https:\/\/onapsis.com\/blog\/sap-patch-day-march-2025\/\" href=\"https:\/\/onapsis.com\/blog\/sap-patch-day-march-2025\/\" data-auth=\"NotApplicable\" data-linkindex=\"11\">SAP Patch Day: March 2025 &#8211; Onapsis<\/a><\/b><\/p>\n<p><strong style=\"color: #014888; font-family: inherit; font-size: 1.6rem; letter-spacing: 0em;\"><u>Resources affected<\/u><\/strong><\/p>\n<div class=\"w-post-elm post_content\">\n<ul>\n<li>SAP NetWeaver (ABAP Class Builder), Versions \u2013 SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 914<\/li>\n<li>\n<div>SAP Commerce Cloud, Version -HY-COM 2205, COM-CLOUD 2211<\/div>\n<\/li>\n<li>\n<div>@sap\/approuter, Version &#8211; 2.6.1 to 16.7.1<\/div>\n<\/li>\n<li>\n<div>SAP PDCE, Version \u2013 S4CORE 102, 103, S4COREOP 104, 105, 106, 107, 108<\/div>\n<\/li>\n<li>\n<div>SAP Business One (Service Layer), Version &#8211; B1_ON_HANA 10.0, SAP-M-BO 10.0<\/div>\n<\/li>\n<li>\n<div>SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML), Versions \u2013 KRNL64UC 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.89, KERNEL 7.93, KERNEL 9.14<\/div>\n<\/li>\n<li>\n<div>SAP NetWeaver Application Server ABAP, Version \u2013 SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 914<\/div>\n<\/li>\n<li>\n<div>SAP Business Warehouse (Process Chains), Version \u2013 DW4CORE 100, DW4CORE 200, DW4CORE 300, DW4CORE 400, DW4CORE 914, SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 750<\/div>\n<\/li>\n<li>\n<div>SAP NetWeaver Application Server Java, Version \u2013 AJAX-RUNTIME 7.50<\/div>\n<\/li>\n<li>\n<div>SAP NetWeaver Enterprise Portal (OBN component), Version \u2013 EP-RUNTIME 7.50<\/div>\n<\/li>\n<li>\n<div>SAP Web Dispatcher and Internet Communication Manager, Versions \u2013 WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.89, WEBDISP 7.93<\/div>\n<\/li>\n<li>\n<div>SAP BusinessObjects Business Intelligence Platform, Version \u2013 ENTERPRISE 430, 2025, 2027 ENTERPRISECLIENTTOOLS 430, 2025<\/div>\n<\/li>\n<li>\n<div>SAP S\/4HANA (Manage Bank Statements), Versions \u2013 S4CORE 107, S4CORE 108<\/div>\n<\/li>\n<li>\n<div>SAP S\/4HANA (RBD), Versions \u2013 S4CORE 102, 103, 104, 105, 106, 107, 108, EA-FINSERV 618, EA-FINSERV 800<\/div>\n<\/li>\n<li>\n<div>SAP Fiori apps (Posting Library), Version \u2013 S4CORE 103, 104, 105, 106, 107, 108<\/div>\n<\/li>\n<li>\n<div>S\/4HANA On-Premise, Version &#8211; S4CORE 105, 106, 107, 108<\/div>\n<\/li>\n<li>\n<div>SAP Permit to Work, Versions &#8211; UIS4HOP1 800, 900<\/div>\n<\/li>\n<li>\n<div>SAP Commerce Cloud and SAP Datahub, , Version -HY_COM 2205, HY_DHUB 2205, COM_CLOUD 2211, DHUB_CLOUD 2211<\/div>\n<\/li>\n<li>\n<div>SAP CRM and SAP S\/4HANA (Interaction Center), Versions &#8211; S4CRM 100, 200, 204, 205, 206, S4FND 102, 103, 104, 105, 106, 107, 108, S4CEXT 107, 108, BBPCRM 701, 702, 712, 713, 714, WEBCUIF 701, 731, 746, 747, 748, 800, 801<\/div>\n<\/li>\n<li>\n<div>SAP Just In Time, Version &#8211; S4CORE 102, 103, 104, 105, 106, 107, ECC-DIMP 618<\/div>\n<\/li>\n<li>\n<div>SAP Electronic Invoicing for Brazil (eDocument Cockpit), Version &#8211; SAP_APPL 617, 618, S4CORE 102, 103, 104, 105, 106, 107, 108<\/div>\n<\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Inprosec through its services, such as the SAP Security Assessment, helps its customers to improve the security levels of their SAP systems. March 2025 Notes Summary and Highlights of the Month Este mes el n\u00famero total de notas ha sido de 25, 4 m\u00e1s que en el periodo anterior. Este mes no ha habido HotNews,&#8230;<\/p>\n","protected":false},"author":6,"featured_media":12698,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[95,61],"tags":[150],"class_list":["post-13015","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sap-notes","category-sap-security-en-2","tag-sap-notes"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.3 (Yoast SEO v27.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>SAP Security Notes, March 2025 - Inprosec<\/title>\n<meta name=\"description\" content=\"All updates to SAP systems notes from february 2025, to stay current and improve the security levels of your SAP systems.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SAP Security Notes, March 2025\" \/>\n<meta property=\"og:description\" content=\"All updates to SAP systems notes from february 2025, to stay current and improve the security levels of your SAP systems.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/\" \/>\n<meta property=\"og:site_name\" content=\"Inprosec\" \/>\n<meta property=\"article:published_time\" content=\"2025-03-19T08:53:14+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/02\/notas-sap-febrero-2025.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Fernando Mosquera\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Fernando Mosquera\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2025\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2025\\\/\"},\"author\":{\"name\":\"Fernando Mosquera\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"headline\":\"SAP Security Notes, March 2025\",\"datePublished\":\"2025-03-19T08:53:14+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2025\\\/\"},\"wordCount\":1030,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2025\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/notas-sap-febrero-2025.jpg\",\"keywords\":[\"SAP Notes\"],\"articleSection\":[\"SAP Notes\",\"SAP Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2025\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2025\\\/\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2025\\\/\",\"name\":\"SAP Security Notes, March 2025 - Inprosec\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2025\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2025\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/notas-sap-febrero-2025.jpg\",\"datePublished\":\"2025-03-19T08:53:14+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"description\":\"All updates to SAP systems notes from february 2025, to stay current and improve the security levels of your SAP systems.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2025\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2025\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2025\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/notas-sap-febrero-2025.jpg\",\"contentUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/notas-sap-febrero-2025.jpg\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2025\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SAP Security Notes, March 2025\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\",\"name\":\"Inprosec\",\"description\":\"Information security is our priority.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\",\"name\":\"Fernando Mosquera\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"caption\":\"Fernando Mosquera\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SAP Security Notes, March 2025 - Inprosec","description":"All updates to SAP systems notes from february 2025, to stay current and improve the security levels of your SAP systems.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/","og_locale":"en_US","og_type":"article","og_title":"SAP Security Notes, March 2025","og_description":"All updates to SAP systems notes from february 2025, to stay current and improve the security levels of your SAP systems.","og_url":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/","og_site_name":"Inprosec","article_published_time":"2025-03-19T08:53:14+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/02\/notas-sap-febrero-2025.jpg","type":"image\/jpeg"}],"author":"Fernando Mosquera","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Fernando Mosquera","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/#article","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/"},"author":{"name":"Fernando Mosquera","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"headline":"SAP Security Notes, March 2025","datePublished":"2025-03-19T08:53:14+00:00","mainEntityOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/"},"wordCount":1030,"commentCount":0,"image":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/02\/notas-sap-febrero-2025.jpg","keywords":["SAP Notes"],"articleSection":["SAP Notes","SAP Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/","url":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/","name":"SAP Security Notes, March 2025 - Inprosec","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/#primaryimage"},"image":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/02\/notas-sap-febrero-2025.jpg","datePublished":"2025-03-19T08:53:14+00:00","author":{"@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"description":"All updates to SAP systems notes from february 2025, to stay current and improve the security levels of your SAP systems.","breadcrumb":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/#primaryimage","url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/02\/notas-sap-febrero-2025.jpg","contentUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/02\/notas-sap-febrero-2025.jpg","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2025\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.inprosec.com\/en\/"},{"@type":"ListItem","position":2,"name":"SAP Security Notes, March 2025"}]},{"@type":"WebSite","@id":"https:\/\/www.inprosec.com\/en\/#website","url":"https:\/\/www.inprosec.com\/en\/","name":"Inprosec","description":"Information security is our priority.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.inprosec.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2","name":"Fernando Mosquera","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","caption":"Fernando Mosquera"}}]}},"_links":{"self":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/13015","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/comments?post=13015"}],"version-history":[{"count":1,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/13015\/revisions"}],"predecessor-version":[{"id":13019,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/13015\/revisions\/13019"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media\/12698"}],"wp:attachment":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media?parent=13015"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/categories?post=13015"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/tags?post=13015"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}