{"id":13115,"date":"2025-05-21T11:01:13","date_gmt":"2025-05-21T09:01:13","guid":{"rendered":"https:\/\/www.inprosec.com\/?p=13115"},"modified":"2025-05-21T11:01:13","modified_gmt":"2025-05-21T09:01:13","slug":"sap-security-notes-may-2025","status":"publish","type":"post","link":"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/","title":{"rendered":"SAP Security Notes, May 2025"},"content":{"rendered":"<p><strong>Inprosec through its services, such as the SAP Security Assessment, helps its customers to improve the security levels of their SAP systems.<\/strong><\/p>\n\n<h2>May 2025 Notes<\/h2>\n<h3>Summary and Highlights of the Month<\/h3>\n<div>\n<p><span class=\"_fadeIn_m1hgl_8\">This <\/span><span class=\"_fadeIn_m1hgl_8\">month, <\/span><span class=\"_fadeIn_m1hgl_8\">the <\/span><span class=\"_fadeIn_m1hgl_8\">total <\/span><span class=\"_fadeIn_m1hgl_8\">number <\/span><span class=\"_fadeIn_m1hgl_8\">of <\/span><span class=\"_fadeIn_m1hgl_8\">notes <\/span><span class=\"_fadeIn_m1hgl_8\">was <\/span><span class=\"_fadeIn_m1hgl_8\">18, <\/span><span class=\"_fadeIn_m1hgl_8\">which <\/span><span class=\"_fadeIn_m1hgl_8\">is <\/span><span class=\"_fadeIn_m1hgl_8\">2 <\/span><span class=\"_fadeIn_m1hgl_8\">fewer <\/span><span class=\"_fadeIn_m1hgl_8\">than <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">the <\/span><span class=\"_fadeIn_m1hgl_8\">previous <\/span><span class=\"_fadeIn_m1hgl_8\">period. <\/span><span class=\"_fadeIn_m1hgl_8\">Two <\/span><span class=\"_fadeIn_m1hgl_8\">Hot <\/span><span class=\"_fadeIn_m1hgl_8\">News <\/span><span class=\"_fadeIn_m1hgl_8\">were <\/span><span class=\"_fadeIn_m1hgl_8\">published <\/span><span class=\"_fadeIn_m1hgl_8\">this <\/span><span class=\"_fadeIn_m1hgl_8\">month, <\/span><span class=\"_fadeIn_m1hgl_8\">one <\/span><span class=\"_fadeIn_m1hgl_8\">fewer <\/span><span class=\"_fadeIn_m1hgl_8\">than <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">the <\/span><span class=\"_fadeIn_m1hgl_8\">previous <\/span><span class=\"_fadeIn_m1hgl_8\">period. <\/span><span class=\"_fadeIn_m1hgl_8\">Regarding <\/span><span class=\"_fadeIn_m1hgl_8\">high-<\/span><span class=\"_fadeIn_m1hgl_8\">criticality <\/span><span class=\"_fadeIn_m1hgl_8\">notes, <\/span><span class=\"_fadeIn_m1hgl_8\">5 <\/span><span class=\"_fadeIn_m1hgl_8\">were <\/span><span class=\"_fadeIn_m1hgl_8\">published\u2014 <\/span><span class=\"_fadeIn_m1hgl_8\">the <\/span><span class=\"_fadeIn_m1hgl_8\">same <\/span><span class=\"_fadeIn_m1hgl_8\">number <\/span><span class=\"_fadeIn_m1hgl_8\">as <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">the <\/span><span class=\"_fadeIn_m1hgl_8\">previous <\/span><span class=\"_fadeIn_m1hgl_8\">period. <\/span><span class=\"_fadeIn_m1hgl_8\">Medium- <\/span><span class=\"_fadeIn_m1hgl_8\">and <\/span><span class=\"_fadeIn_m1hgl_8\">low-<\/span><span class=\"_fadeIn_m1hgl_8\">criticality <\/span><span class=\"_fadeIn_m1hgl_8\">notes <\/span><span class=\"_fadeIn_m1hgl_8\">will <\/span><span class=\"_fadeIn_m1hgl_8\">not <\/span><span class=\"_fadeIn_m1hgl_8\">be <\/span><span class=\"_fadeIn_m1hgl_8\">reviewed, <\/span><span class=\"_fadeIn_m1hgl_8\">so <\/span><strong><span class=\"_fadeIn_m1hgl_8\">we <\/span><span class=\"_fadeIn_m1hgl_8\">will <\/span><span class=\"_fadeIn_m1hgl_8\">detail <\/span><span class=\"_fadeIn_m1hgl_8\">a <\/span><span class=\"_fadeIn_m1hgl_8\">total <\/span><span class=\"_fadeIn_m1hgl_8\">of <\/span><span class=\"_fadeIn_m1hgl_8\">7 <\/span><\/strong><span class=\"_fadeIn_m1hgl_8\"><strong>notes<\/strong> (<\/span><span class=\"_fadeIn_m1hgl_8\">all <\/span><span class=\"_fadeIn_m1hgl_8\">with <\/span><span class=\"_fadeIn_m1hgl_8\">a <\/span><span class=\"_fadeIn_m1hgl_8\">CVSS <\/span><span class=\"_fadeIn_m1hgl_8\">score <\/span><span class=\"_fadeIn_m1hgl_8\">of <\/span><span class=\"_fadeIn_m1hgl_8\" style=\"color: #ffcc00;\"><strong>7<\/strong> <\/span><span class=\"_fadeIn_m1hgl_8\">or <\/span><span class=\"_fadeIn_m1hgl_8\">higher).<\/span><\/p>\n<p><span class=\"_fadeIn_m1hgl_8\">We <\/span><span class=\"_fadeIn_m1hgl_8\">have <\/span><span class=\"_fadeIn_m1hgl_8\">a <\/span><strong><span class=\"_fadeIn_m1hgl_8\">total <\/span><span class=\"_fadeIn_m1hgl_8\">of <\/span><span class=\"_fadeIn_m1hgl_8\">18 <\/span><span class=\"_fadeIn_m1hgl_8\">notes <\/span><\/strong><span class=\"_fadeIn_m1hgl_8\">for <\/span><span class=\"_fadeIn_m1hgl_8\">the <\/span><span class=\"_fadeIn_m1hgl_8\">entire <\/span><span class=\"_fadeIn_m1hgl_8\">month (<\/span><span class=\"_fadeIn_m1hgl_8\">16 <\/span><span class=\"_fadeIn_m1hgl_8\">new <\/span><span class=\"_fadeIn_m1hgl_8\">and <\/span><span class=\"_fadeIn_m1hgl_8\">2 <\/span><span class=\"_fadeIn_m1hgl_8\">updates <\/span><span class=\"_fadeIn_m1hgl_8\">of <\/span><span class=\"_fadeIn_m1hgl_8\">notes <\/span><span class=\"_fadeIn_m1hgl_8\">published <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">previous <\/span><span class=\"_fadeIn_m1hgl_8\">months).<\/span><\/p>\n<p data-start=\"563\" data-end=\"655\"><span class=\"_fadeIn_m1hgl_8\">We <\/span><span class=\"_fadeIn_m1hgl_8\">will <\/span><span class=\"_fadeIn_m1hgl_8\">review <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">detail <\/span><span class=\"_fadeIn_m1hgl_8\">a <\/span><span class=\"_fadeIn_m1hgl_8\">total <\/span><span class=\"_fadeIn_m1hgl_8\">of <\/span><span class=\"_fadeIn_m1hgl_8\">7 <\/span><span class=\"_fadeIn_m1hgl_8\">notes, <\/span><span class=\"_fadeIn_m1hgl_8\">all <\/span><span class=\"_fadeIn_m1hgl_8\">of <\/span><span class=\"_fadeIn_m1hgl_8\">which <\/span><span class=\"_fadeIn_m1hgl_8\">are <\/span><span class=\"_fadeIn_m1hgl_8\">high-<\/span><span class=\"_fadeIn_m1hgl_8\">criticality <\/span><span class=\"_fadeIn_m1hgl_8\">and <\/span><span class=\"_fadeIn_m1hgl_8\">Hot <\/span><span class=\"_fadeIn_m1hgl_8\">News:<\/span><\/p>\n<ol start=\"1\">\n<li><strong><span class=\"_fadeIn_m1hgl_8\">The <\/span><span class=\"_fadeIn_m1hgl_8\">most <\/span><span class=\"_fadeIn_m1hgl_8\">critical <\/span><span class=\"_fadeIn_m1hgl_8\">note <\/span><span class=\"_fadeIn_m1hgl_8\">of <\/span><span class=\"_fadeIn_m1hgl_8\">the <\/span><\/strong><span class=\"_fadeIn_m1hgl_8\"><strong>month<\/strong> <strong>(<\/strong><\/span><strong><span class=\"_fadeIn_m1hgl_8\">CVSS <\/span><span class=\"_fadeIn_m1hgl_8\"><span style=\"color: #ff0000;\">10,0<\/span>) <\/span><\/strong><span class=\"_fadeIn_m1hgl_8\">is <\/span><span class=\"_fadeIn_m1hgl_8\">a <\/span><span class=\"_fadeIn_m1hgl_8\">Hot <\/span><span class=\"_fadeIn_m1hgl_8\">News <\/span><span class=\"_fadeIn_m1hgl_8\">with <\/span><span class=\"_fadeIn_m1hgl_8\">the <\/span><span class=\"_fadeIn_m1hgl_8\">highest <\/span><span class=\"_fadeIn_m1hgl_8\">possible <\/span><span class=\"_fadeIn_m1hgl_8\">CVSS <\/span><span class=\"_fadeIn_m1hgl_8\">score. <\/span><span class=\"_fadeIn_m1hgl_8\">It <\/span><span class=\"_fadeIn_m1hgl_8\">is <\/span><span class=\"_fadeIn_m1hgl_8\">an <\/span><span class=\"_fadeIn_m1hgl_8\">update <\/span><span class=\"_fadeIn_m1hgl_8\">of <\/span><span class=\"_fadeIn_m1hgl_8\">a <\/span><span class=\"_fadeIn_m1hgl_8\">note <\/span><span class=\"_fadeIn_m1hgl_8\">released <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">April: <strong>\u201c<\/strong><\/span><strong><span class=\"_fadeIn_m1hgl_8\">Missing <\/span><span class=\"_fadeIn_m1hgl_8\">Authorization <\/span><span class=\"_fadeIn_m1hgl_8\">Check <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">SAP <\/span><span class=\"_fadeIn_m1hgl_8\">NetWeaver (<\/span><span class=\"_fadeIn_m1hgl_8\">Visual <\/span><span class=\"_fadeIn_m1hgl_8\">Composer <\/span><span class=\"_fadeIn_m1hgl_8\">development <\/span><span class=\"_fadeIn_m1hgl_8\">server)\u201d.<\/span><\/strong><\/li>\n<li><span class=\"_fadeIn_m1hgl_8\">The <\/span><span class=\"_fadeIn_m1hgl_8\">next <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">severity <strong>(<\/strong><\/span><strong><span class=\"_fadeIn_m1hgl_8\">CVSS <\/span><span class=\"_fadeIn_m1hgl_8\"><span style=\"color: #ff0000;\">9,1<\/span>) <\/span><\/strong><span class=\"_fadeIn_m1hgl_8\">is <\/span><span class=\"_fadeIn_m1hgl_8\">a <\/span><span class=\"_fadeIn_m1hgl_8\">Hot <\/span><span class=\"_fadeIn_m1hgl_8\">News <\/span><span class=\"_fadeIn_m1hgl_8\">related <\/span><span class=\"_fadeIn_m1hgl_8\">to <strong>\u201c<\/strong><\/span><strong><span class=\"_fadeIn_m1hgl_8\">Insecure <\/span><span class=\"_fadeIn_m1hgl_8\">Deserialization <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">SAP <\/span><span class=\"_fadeIn_m1hgl_8\">NetWeaver (<\/span><span class=\"_fadeIn_m1hgl_8\">Visual <\/span><span class=\"_fadeIn_m1hgl_8\">Composer <\/span><span class=\"_fadeIn_m1hgl_8\">development <\/span><\/strong><span class=\"_fadeIn_m1hgl_8\"><strong>server)\u201d<\/strong>.<\/span><\/li>\n<li>\n<div>T<span class=\"_fadeIn_m1hgl_8\">he <\/span><span class=\"_fadeIn_m1hgl_8\">next <strong>(<\/strong><\/span><strong><span class=\"_fadeIn_m1hgl_8\">CVSS <\/span><span class=\"_fadeIn_m1hgl_8\"><span style=\"color: #ff0000;\">8,6<\/span>) <\/span><\/strong><span class=\"_fadeIn_m1hgl_8\">is <\/span><span class=\"_fadeIn_m1hgl_8\">a <\/span><span class=\"_fadeIn_m1hgl_8\">note <\/span><span class=\"_fadeIn_m1hgl_8\">related <\/span><span class=\"_fadeIn_m1hgl_8\">to <strong>\u201c<\/strong><\/span><strong><span class=\"_fadeIn_m1hgl_8\">Multiple <\/span><span class=\"_fadeIn_m1hgl_8\">vulnerabilities <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">SAP <\/span><span class=\"_fadeIn_m1hgl_8\">Supplier <\/span><span class=\"_fadeIn_m1hgl_8\">Relationship <\/span><span class=\"_fadeIn_m1hgl_8\">Management (<\/span><span class=\"_fadeIn_m1hgl_8\">Live <\/span><span class=\"_fadeIn_m1hgl_8\">Auction <\/span><span class=\"_fadeIn_m1hgl_8\">Cockpit)\u201d.<\/span><\/strong><\/div>\n<\/li>\n<li><span class=\"_fadeIn_m1hgl_8\">The <\/span><span class=\"_fadeIn_m1hgl_8\">following <strong>(<\/strong><\/span><strong><span class=\"_fadeIn_m1hgl_8\">CVSS <\/span><span class=\"_fadeIn_m1hgl_8\"><span style=\"color: #ff0000;\">8,3<\/span>) <\/span><\/strong><span class=\"_fadeIn_m1hgl_8\">is <\/span><span class=\"_fadeIn_m1hgl_8\">a <\/span><span class=\"_fadeIn_m1hgl_8\">note <\/span><span class=\"_fadeIn_m1hgl_8\">related <\/span><span class=\"_fadeIn_m1hgl_8\">to <strong>\u201c<\/strong><\/span><strong><span class=\"_fadeIn_m1hgl_8\">Code <\/span><span class=\"_fadeIn_m1hgl_8\">Injection <\/span><span class=\"_fadeIn_m1hgl_8\">Vulnerability <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">SAP <\/span><span class=\"_fadeIn_m1hgl_8\">S\/<\/span><span class=\"_fadeIn_m1hgl_8\">4HANA <\/span><span class=\"_fadeIn_m1hgl_8\">Cloud <\/span><span class=\"_fadeIn_m1hgl_8\">Private <\/span><span class=\"_fadeIn_m1hgl_8\">Edition <\/span><span class=\"_fadeIn_m1hgl_8\">or <\/span><span class=\"_fadeIn_m1hgl_8\">On <\/span><span class=\"_fadeIn_m1hgl_8\">Premise (<\/span><span class=\"_fadeIn_m1hgl_8\">SCM <\/span><span class=\"_fadeIn_m1hgl_8\">Master <\/span><span class=\"_fadeIn_m1hgl_8\">Data <\/span><span class=\"_fadeIn_m1hgl_8\">Layer (<\/span><span class=\"_fadeIn_m1hgl_8\">MDL))\u201d.<\/span><\/strong><\/li>\n<li><span class=\"_fadeIn_m1hgl_8\">The <\/span><span class=\"_fadeIn_m1hgl_8\">next<strong> (<\/strong><\/span><strong><span class=\"_fadeIn_m1hgl_8\">CVSS <\/span><span class=\"_fadeIn_m1hgl_8\"><span style=\"color: #ffcc00;\">7,9<\/span>) <\/span><\/strong><span class=\"_fadeIn_m1hgl_8\">concerns <strong>\u201c<\/strong><\/span><strong><span class=\"_fadeIn_m1hgl_8\">Information <\/span><span class=\"_fadeIn_m1hgl_8\">Disclosure <\/span><span class=\"_fadeIn_m1hgl_8\">Vulnerability <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">SAP <\/span><span class=\"_fadeIn_m1hgl_8\">Business <\/span><span class=\"_fadeIn_m1hgl_8\">Objects <\/span><span class=\"_fadeIn_m1hgl_8\">Business <\/span><span class=\"_fadeIn_m1hgl_8\">Intelligence <\/span><span class=\"_fadeIn_m1hgl_8\">Platform (<\/span><\/strong><span class=\"_fadeIn_m1hgl_8\"><strong>PMW)\u201d<\/strong>.<\/span><\/li>\n<li><span class=\"_fadeIn_m1hgl_8\">Finally, <\/span><span class=\"_fadeIn_m1hgl_8\">there <\/span><span class=\"_fadeIn_m1hgl_8\">are <\/span><span class=\"_fadeIn_m1hgl_8\">two <\/span><span class=\"_fadeIn_m1hgl_8\">high-<\/span><span class=\"_fadeIn_m1hgl_8\">criticality <\/span><span class=\"_fadeIn_m1hgl_8\">notes <strong>(<\/strong><\/span><strong><span class=\"_fadeIn_m1hgl_8\">CVSS <\/span><\/strong><span class=\"_fadeIn_m1hgl_8\"><strong><span style=\"color: #ffcc00;\">7,7<\/span>)<\/strong>: <\/span><span class=\"_fadeIn_m1hgl_8\">the <\/span><span class=\"_fadeIn_m1hgl_8\">first <\/span><span class=\"_fadeIn_m1hgl_8\">one <\/span><span class=\"_fadeIn_m1hgl_8\">related <\/span><span class=\"_fadeIn_m1hgl_8\">to <strong>\u201c<\/strong><\/span><strong><span class=\"_fadeIn_m1hgl_8\">Missing <\/span><span class=\"_fadeIn_m1hgl_8\">Authorization <\/span><span class=\"_fadeIn_m1hgl_8\">Check <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">SAP <\/span><span class=\"_fadeIn_m1hgl_8\">Landscape <\/span><span class=\"_fadeIn_m1hgl_8\">Transformation (<\/span><span class=\"_fadeIn_m1hgl_8\">PCL <\/span><\/strong><span class=\"_fadeIn_m1hgl_8\"><strong>Basis)\u201d<\/strong>, <\/span><span class=\"_fadeIn_m1hgl_8\">and <\/span><span class=\"_fadeIn_m1hgl_8\">the <\/span><span class=\"_fadeIn_m1hgl_8\">second <\/span><span class=\"_fadeIn_m1hgl_8\">one <\/span><span class=\"_fadeIn_m1hgl_8\">is <\/span><span class=\"_fadeIn_m1hgl_8\">an <\/span><span class=\"_fadeIn_m1hgl_8\">update <\/span><span class=\"_fadeIn_m1hgl_8\">of <\/span><span class=\"_fadeIn_m1hgl_8\">a <\/span><span class=\"_fadeIn_m1hgl_8\">note <\/span><span class=\"_fadeIn_m1hgl_8\">originally <\/span><span class=\"_fadeIn_m1hgl_8\">released <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">July <\/span><span class=\"_fadeIn_m1hgl_8\">2024, <\/span><span class=\"_fadeIn_m1hgl_8\">related <\/span><span class=\"_fadeIn_m1hgl_8\">to <strong>\u201c<\/strong><\/span><strong><span class=\"_fadeIn_m1hgl_8\">Missing <\/span><span class=\"_fadeIn_m1hgl_8\">Authorization <\/span><span class=\"_fadeIn_m1hgl_8\">Check <\/span><span class=\"_fadeIn_m1hgl_8\">in <\/span><span class=\"_fadeIn_m1hgl_8\">SAP <\/span><\/strong><span class=\"_fadeIn_m1hgl_8\"><strong>PDCE\u201d<\/strong>.<\/span><\/li>\n<li>\n<div><span class=\"_fadeIn_m1hgl_8\">This <\/span><span class=\"_fadeIn_m1hgl_8\">month, <\/span><span class=\"_fadeIn_m1hgl_8\">the <\/span><span class=\"_fadeIn_m1hgl_8\">most <\/span><span class=\"_fadeIn_m1hgl_8\">prevalent <\/span><span class=\"_fadeIn_m1hgl_8\">type <\/span><span class=\"_fadeIn_m1hgl_8\">is <strong>\u201c<\/strong><\/span><strong><span class=\"_fadeIn_m1hgl_8\">Missing <\/span><span class=\"_fadeIn_m1hgl_8\">Authorization <\/span><\/strong><span class=\"_fadeIn_m1hgl_8\"><strong>Check\u201d<\/strong> (<\/span><span class=\"_fadeIn_m1hgl_8\">7 <\/span><span class=\"_fadeIn_m1hgl_8\">out <\/span><span class=\"_fadeIn_m1hgl_8\">of <\/span><span class=\"_fadeIn_m1hgl_8\">18 <\/span><span class=\"_fadeIn_m1hgl_8\">on <\/span><span class=\"_fadeIn_m1hgl_8\">Patch <\/span><span class=\"_fadeIn_m1hgl_8\">Day).<\/span><\/div>\n<div><\/div>\n<\/li>\n<\/ol>\n<p><span class=\"_fadeIn_m1hgl_8\">The <\/span><span class=\"_fadeIn_m1hgl_8\">chart <\/span><span class=\"_fadeIn_m1hgl_8\">shows <\/span><span style=\"text-decoration: underline;\"><strong><span class=\"_fadeIn_m1hgl_8\">the <\/span><span class=\"_fadeIn_m1hgl_8\">classification <\/span><span class=\"_fadeIn_m1hgl_8\">of <\/span><span class=\"_fadeIn_m1hgl_8\">the <\/span><span class=\"_fadeIn_m1hgl_8\">May <\/span><\/strong><\/span><span class=\"_fadeIn_m1hgl_8\"><span style=\"text-decoration: underline;\"><strong>notes<\/strong><\/span>, <\/span><span class=\"_fadeIn_m1hgl_8\">as <\/span><span class=\"_fadeIn_m1hgl_8\">well <\/span><span class=\"_fadeIn_m1hgl_8\">as <\/span><span class=\"_fadeIn_m1hgl_8\">the <\/span><span class=\"_fadeIn_m1hgl_8\">trend <\/span><span class=\"_fadeIn_m1hgl_8\">and <\/span><span class=\"_fadeIn_m1hgl_8\">classification <\/span><span class=\"_fadeIn_m1hgl_8\">of <\/span><span class=\"_fadeIn_m1hgl_8\">the <\/span><span class=\"_fadeIn_m1hgl_8\">past <\/span><span class=\"_fadeIn_m1hgl_8\">5 <\/span><span class=\"_fadeIn_m1hgl_8\">months (<\/span><span class=\"_fadeIn_m1hgl_8\">only <\/span><span class=\"_fadeIn_m1hgl_8\">notes <\/span><span class=\"_fadeIn_m1hgl_8\">from <\/span><span class=\"_fadeIn_m1hgl_8\">Security <\/span><span class=\"_fadeIn_m1hgl_8\">Tuesday \/ <\/span><span class=\"_fadeIn_m1hgl_8\">Patch <\/span><span class=\"_fadeIn_m1hgl_8\">Day \u2013 <\/span><span class=\"_fadeIn_m1hgl_8\">by <\/span><span class=\"_fadeIn_m1hgl_8\">SAP).<\/span><\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-13117\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/05\/image.png\" alt=\"\" width=\"802\" height=\"530\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/05\/image.png 912w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/05\/image-300x198.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/05\/image-600x397.png 600w\" sizes=\"(max-width: 802px) 100vw, 802px\" \/><\/p>\n<h3>Full details<\/h3>\n<p>The <strong>complete detail of the most relevant notes<\/strong> is as follows:<\/p>\n<ol start=\"1\">\n<li>\n<div><b>Update &#8211; Missing Authorization check in SAP NetWeaver (Visual Composer development server)<\/b><b><u>\u00a0(<\/u><\/b><b><u><a href=\"https:\/\/me.sap.com\/notes\/3594142\" target=\"_blank\" rel=\"noopener noreferrer\">3594142<\/a><\/u><\/b><b><u>)<\/u>:<\/b>\u00a0SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system. The solution is to apply authentication requirements and authorization restrictions reflected in this note. There is a workaround explained in\u00a0<u><a href=\"https:\/\/me.sap.com\/notes\/3593336\/E\" target=\"_blank\" rel=\"noopener noreferrer\">KBA 3593336<\/a>.<\/u><b>\u00a0CVSS v3\u00a0Base Score\u00a0<\/b><span style=\"color: #ff0000;\"><b>10,0<\/b><\/span><b>\/ 10 [<\/b><b><u><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-31324\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2025-31324<\/a><\/u><\/b><b>]<\/b><\/div>\n<\/li>\n<li>\n<div><b>Insecure Deserialization in SAP NetWeaver (Visual Composer development server)<u>\u00a0(<\/u><\/b><b><u><a href=\"https:\/\/me.sap.com\/notes\/3604119\" target=\"_blank\" rel=\"noopener noreferrer\">3604119<\/a><\/u><\/b><b><u>)<\/u>:\u00a0<\/b>SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system. Applying this note removes the deserialization, which completely resolves this vulnerability. There is a workaround in\u00a0<a href=\"https:\/\/me.sap.com\/notes\/3593336\/E\" target=\"_blank\" rel=\"noopener noreferrer\">KBA 3593336<\/a>\u00a0<b>CVSS v3\u00a0Base Score\u00a0<\/b><b><span style=\"color: #ff0000;\">9,1<\/span>\u200b<\/b><b>\/ 10 [<\/b><b><u><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-42999\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2025-42999<\/a><\/u><\/b><b>]<\/b><\/div>\n<\/li>\n<li>\n<div><b>Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)\u00a0(<\/b><b><u><a href=\"https:\/\/me.sap.com\/notes\/3578900\" target=\"_blank\" rel=\"noopener noreferrer\">3578900<\/a><\/u><\/b><b>):\u00a0<\/b>Multiple critical vulnerabilities including Blind XXE, XSS, Open Redirect, Information Disclosure, and Insecure Deserialization affect the Live Auction Cockpit component of SAP SRM due to the use of a deprecated Java Applet, and are resolved by removing the applet through updates to versions that use only DHTML, as detailed in SAP Notes 2369341, 2171391, and 1715441.\u00a0<b>\u00a0CVSS v3\u00a0Base Score\u00a0<\/b><span style=\"color: #ff0000;\"><b>8,6<\/b><\/span><b>\/ 10 [<\/b><b><u><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-30018\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2025-30018<\/a><\/u><\/b><b>]<\/b><\/div>\n<\/li>\n<li>\n<div><b>Code injection vulnerability in SAP S\/4HANA Cloud Private Edition or On Premise (SCM Master Data Layer (MDL))\u00a0(<\/b><b><u><a href=\"https:\/\/me.sap.com\/notes\/3600859\" target=\"_blank\" rel=\"noopener noreferrer\">3600859<\/a><\/u><\/b><b>):\u00a0<\/b>A code injection vulnerability in SAP S\/4HANA Cloud Private Edition or on-premise (SCM Master Data Layer) allows authenticated users to remotely replace ABAP programs due to missing input validation and authorization checks, and is resolved by deprecating the obsolete function module through a\u00a0correction that disables its execution.<b>\u00a0CVSS v3\u00a0Base Score\u00a0<\/b><span style=\"color: #ff0000;\"><b>8,3<\/b><\/span><b>\/ 10\u00a0 [<\/b><b><u><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-43010\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2025-43010<\/a><\/u><\/b><b>]<\/b><\/div>\n<\/li>\n<li>\n<div><b>Information Disclosure Vulnerability in SAP Business Objects Business Intelligence Platform (PMW): (<\/b><b><u><a href=\"https:\/\/me.sap.com\/notes\/3586013\" target=\"_blank\" rel=\"noopener noreferrer\">3586013<\/a><\/u><\/b><b>):<\/b>An information exposure vulnerability in Promotion Management Wizard (PMW) allows unauthorized access to restricted data due to the ability to launch certain executables, and is resolved by restricting unnecessary information for end users through the implementation of the provided patches. There is a workaround in the note.\u00a0<b>CVSS v3\u00a0Base Score<span style=\"color: #ffcc00;\">\u00a0<\/span><\/b><span style=\"color: #ffcc00;\"><b>7,9<\/b><\/span><b>\/ 10\u00a0 [<\/b><b><u><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-43000\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2025-43000<\/a><\/u><\/b><b>]<\/b><\/div>\n<\/li>\n<li>\n<div><b>Missing Authorization Check in SAP Landscape Transformation (PCL Basis)\u00a0(<\/b><b><u><a href=\"https:\/\/me.sap.com\/notes\/3591978\" target=\"_blank\" rel=\"noopener noreferrer\">3591978<\/a><\/u><\/b><b>):\u00a0<\/b>A missing authorization check in SAP Landscape Transformation&#8217;s PCL Basis module allows authenticated users to access restricted data, impacting confidentiality, and is resolved by enhancing the affected remote-enabled function modules with proper authorization checks as detailed in the provided correction instructions or support packages. There isn&#8217;t workaround for this note.\u00a0<b>CVSS v3\u00a0Base Score\u00a0<\/b><span style=\"color: #ffcc00;\"><b>7,7<\/b><\/span><b>\/ 10 [<\/b><b><u><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-43011\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2025-43011<\/a><\/u><\/b><b>]<\/b><\/div>\n<\/li>\n<li><b>Update &#8211; Missing Authorization check in SAP PDCE\u00a0(<\/b><b><u><a href=\"https:\/\/me.sap.com\/notes\/3483344\" target=\"_blank\" rel=\"noopener noreferrer\">3483344<\/a><\/u><\/b><b>):\u00a0<\/b>A privilege escalation vulnerability in PDCE allows authenticated users to access sensitive information due to missing authorization checks, and is resolved in version 19 by deactivating the affected functions and providing updated correction instructions for SEM-BW 600 SP01 to SP015 to simplify implementation without complex prerequisites. There is not workaround.\u00a0<b>CVSS v3\u00a0Base Score\u00a0<\/b><span style=\"color: #ffcc00;\"><b>7,7<\/b><\/span><b>\/ 10 [<\/b><b><u><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-39592\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2024-39592<\/a><\/u><\/b><b>]<\/b><\/li>\n<\/ol>\n<h3 style=\"font-weight: 400;\"><strong>Reference links<\/strong><\/h3>\n<p>Other references, from SAP and Onapsis (may):<\/p>\n<p><b><u><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/may-2025.html\" target=\"_blank\" rel=\"noopener noreferrer\">SAP Security Patch Day &#8211; May 2025<\/a><\/u><\/b><\/p>\n<p><b><u><a href=\"https:\/\/onapsis.com\/blog\/sap-security-patch-day-may-2025\/\" target=\"_blank\" rel=\"noopener noreferrer\">SAP Patch Day: May 2025 &#8211; Onapsis<\/a><\/u><\/b><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong style=\"color: #014888; font-family: inherit; font-size: 1.6rem; letter-spacing: 0em;\"><u>Resources affected<\/u><\/strong><\/p>\n<div class=\"w-post-elm post_content\">\n<p>The full list of affected systems\/components is as follows:<\/p>\n<ul>\n<li>\n<div>SAP NetWeaver (Visual Composer development server) Version \u2013 VCFRAMEWORK 7.50<\/div>\n<\/li>\n<li>\n<div>SAP Supplier Relationship Management (Live Auction Cockpit) Version \u2013 SRM_SERVER 7.14<\/div>\n<\/li>\n<li>\n<div>SAP S\/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) Versions \u2013 S4CORE 102, 103, 104, 105, 106, 107, 108, SCM_BASIS 700, 701, 702, 712, 713, 714<\/div>\n<\/li>\n<li>SAP NetWeaver Application Server ABAP, Versions &#8211; KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93<\/li>\n<li>\n<div>SAP Business Objects Business Intelligence Platform (PMW) Versions \u2013 ENTERPRISE 430, 2025, 2027<\/div>\n<\/li>\n<li>\n<div>SAP Landscape Transformation (PCL Basis) Versions \u2013 DMIS 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2018_1_752, 2020, S4CORE 102, 103, 104, 105, 106, 107, 108<\/div>\n<\/li>\n<li>\n<div>SAP PDCE Versions \u2013 S4CORE 102, 103, S4COREOP 104, 105, 106, 107, 108<\/div>\n<\/li>\n<li>\n<div>SAP Gateway Client Versions \u2013 SAP_GWFND 752, 753, 754, 755, 756, 757, 758<\/div>\n<\/li>\n<li>\n<div>SAP S\/4HANA (Private Cloud &amp; On-Premise) Versions &#8211; S4CRM 204, 205, 206, S4CEXT 107, 108, BBPCRM 702, 712, 713, 714<\/div>\n<\/li>\n<li>\n<div>SAP Service Parts Management (SPM) Versions &#8211; SAP_APPL 600, 602, 603, 604, 605, 606, 616, 617, 618, SAPSCORE 111, \u00a0SAPSCORE 116,\u00a0S4CORE 100, 101, 102<\/div>\n<\/li>\n<li>\n<div>SAP NetWeaver Application Server ABAP and ABAP Platform Versions &#8211; SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758<\/div>\n<\/li>\n<li>\n<div>SAP Supplier Relationship Management (Master Data Management Catalog Version \u2013 SRM_MDM_CAT 7.52<\/div>\n<\/li>\n<li>\n<div>SAP S\/4HANA HCM Portugal and SAP ERP HCM Portugal Versions \u2013 S4HCMCPT 100, 101, SAP_HRCPT 600, 604, 608<\/div>\n<\/li>\n<li>\n<div>SAP Digital Manufacturing (Production Operator Dashboard) Version \u2013 CTNR-DME-PODFOUNDATION-MS 1.0<\/div>\n<\/li>\n<li>\n<div>SAP Data Services Management Console Version \u2013 SBOP DS JOB SERVER 4.3<\/div>\n<\/li>\n<li>\n<div>SAP S4\/HANA (OData meta-data property) Versions &#8211; S4CORE 102, 103, 104, 105, 106<\/div>\n<\/li>\n<li>\n<div>SAP GUI for Windows Version \u2013 BC-FES-GUI 8.00<\/div>\n<\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Inprosec through its services, such as the SAP Security Assessment, helps its customers to improve the security levels of their SAP systems. May 2025 Notes Summary and Highlights of the Month This month, the total number of notes was 18, which is 2 fewer than in the previous period. Two Hot News were published this&#8230;<\/p>\n","protected":false},"author":8,"featured_media":13117,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[95,61],"tags":[150],"class_list":["post-13115","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sap-notes","category-sap-security-en-2","tag-sap-notes"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.3 (Yoast SEO v27.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>SAP Security Notes, May 2025 - Inprosec<\/title>\n<meta name=\"description\" content=\"All updates to SAP systems notes from may 2025, to stay current and improve the security levels of your SAP systems.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SAP Security Notes, May 2025\" \/>\n<meta property=\"og:description\" content=\"All updates to SAP systems notes from may 2025, to stay current and improve the security levels of your SAP systems.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/\" \/>\n<meta property=\"og:site_name\" content=\"Inprosec\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-21T09:01:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/05\/image.png\" \/>\n\t<meta property=\"og:image:width\" content=\"912\" \/>\n\t<meta property=\"og:image:height\" content=\"603\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Inprosec\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Inprosec\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-may-2025\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-may-2025\\\/\"},\"author\":{\"name\":\"Inprosec\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/59527c2df689eca243000fe234ea2fd9\"},\"headline\":\"SAP Security Notes, May 2025\",\"datePublished\":\"2025-05-21T09:01:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-may-2025\\\/\"},\"wordCount\":1087,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-may-2025\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/image.png\",\"keywords\":[\"SAP Notes\"],\"articleSection\":[\"SAP Notes\",\"SAP Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-may-2025\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-may-2025\\\/\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-may-2025\\\/\",\"name\":\"SAP Security Notes, May 2025 - Inprosec\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-may-2025\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-may-2025\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/image.png\",\"datePublished\":\"2025-05-21T09:01:13+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/59527c2df689eca243000fe234ea2fd9\"},\"description\":\"All updates to SAP systems notes from may 2025, to stay current and improve the security levels of your SAP systems.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-may-2025\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-may-2025\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-may-2025\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/image.png\",\"contentUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/image.png\",\"width\":912,\"height\":603},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-may-2025\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SAP Security Notes, May 2025\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\",\"name\":\"Inprosec\",\"description\":\"Information security is our priority.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/59527c2df689eca243000fe234ea2fd9\",\"name\":\"Inprosec\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ddd6894cc34f99550833ccd68dc42b660c6ede2266ffe95938be547f854910e6?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ddd6894cc34f99550833ccd68dc42b660c6ede2266ffe95938be547f854910e6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ddd6894cc34f99550833ccd68dc42b660c6ede2266ffe95938be547f854910e6?s=96&d=mm&r=g\",\"caption\":\"Inprosec\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SAP Security Notes, May 2025 - Inprosec","description":"All updates to SAP systems notes from may 2025, to stay current and improve the security levels of your SAP systems.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/","og_locale":"en_US","og_type":"article","og_title":"SAP Security Notes, May 2025","og_description":"All updates to SAP systems notes from may 2025, to stay current and improve the security levels of your SAP systems.","og_url":"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/","og_site_name":"Inprosec","article_published_time":"2025-05-21T09:01:13+00:00","og_image":[{"width":912,"height":603,"url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/05\/image.png","type":"image\/png"}],"author":"Inprosec","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Inprosec","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/#article","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/"},"author":{"name":"Inprosec","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/59527c2df689eca243000fe234ea2fd9"},"headline":"SAP Security Notes, May 2025","datePublished":"2025-05-21T09:01:13+00:00","mainEntityOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/"},"wordCount":1087,"commentCount":0,"image":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/05\/image.png","keywords":["SAP Notes"],"articleSection":["SAP Notes","SAP Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/","url":"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/","name":"SAP Security Notes, May 2025 - Inprosec","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/#primaryimage"},"image":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/05\/image.png","datePublished":"2025-05-21T09:01:13+00:00","author":{"@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/59527c2df689eca243000fe234ea2fd9"},"description":"All updates to SAP systems notes from may 2025, to stay current and improve the security levels of your SAP systems.","breadcrumb":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/#primaryimage","url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/05\/image.png","contentUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/05\/image.png","width":912,"height":603},{"@type":"BreadcrumbList","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-may-2025\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.inprosec.com\/en\/"},{"@type":"ListItem","position":2,"name":"SAP Security Notes, May 2025"}]},{"@type":"WebSite","@id":"https:\/\/www.inprosec.com\/en\/#website","url":"https:\/\/www.inprosec.com\/en\/","name":"Inprosec","description":"Information security is our priority.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.inprosec.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/59527c2df689eca243000fe234ea2fd9","name":"Inprosec","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/ddd6894cc34f99550833ccd68dc42b660c6ede2266ffe95938be547f854910e6?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/ddd6894cc34f99550833ccd68dc42b660c6ede2266ffe95938be547f854910e6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ddd6894cc34f99550833ccd68dc42b660c6ede2266ffe95938be547f854910e6?s=96&d=mm&r=g","caption":"Inprosec"}}]}},"_links":{"self":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/13115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/comments?post=13115"}],"version-history":[{"count":3,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/13115\/revisions"}],"predecessor-version":[{"id":13125,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/13115\/revisions\/13125"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media\/13117"}],"wp:attachment":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media?parent=13115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/categories?post=13115"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/tags?post=13115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}