SAP June 2025 Security Patch Day fixed critical NetWeaver bug
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-23192 | SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser enabling the attacker to potentially access sensitive session information, modify or make browser information unavailable. This leads to a high impact on confidentiality and low impact on integrity, availability. NVD description · AI analysis pending | 7.6 | <1% |
| — | ||
| CVE-2025-42977 | SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input paths provided by a high-privileged user. SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input paths provided by a high-privileged user. This allows an attacker to read or modify arbitrary files, resulting in a high impact on confidentiality and a low impact on integrity. NVD description · AI analysis pending | 7.6 | <1% | — | — | ||
| CVE-2025-42982 | SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system credentials. SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system credentials. This causes high impact on confidentiality, integrity and availability of the application. NVD description · AI analysis pending | 8.8 | <1% | — | — | ||
| CVE-2025-42983 | SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or rendering the system unusable. On successful exploitation, an attacker can completely delete database entries but is not able to read any data. NVD description · AI analysis pending | 8.5 | <1% | — | — | ||
| CVE-2025-42989 | RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact both integrity and availability of the application. NVD description · AI analysis pending | 9.6 | <1% | — | — | ||
| CVE-2025-42994 | SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the application. NVD description · AI analysis pending | 7.5 | <1% | — | — |
Full article325 words · extracted from securityaffairs.com · click to collapse

SAP fixed a critical NetWeaver flaw that let attackers bypass authorization and escalate privileges. Patch released in June 2025 Security Patch.
SAP June 2025 Security Patch addressed a critical NetWeaver vulnerability, tracked as CVE-2025-42989 (CVSS score of 9.6), allowing threat actors to bypass authorization checks and escalate their privileges.
“RFC inbound processing does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.” reads the advisory. “On successful exploitation the attacker could critically impact both integrity and availability of the application.”
The flaw resides in SAP’s Remote Function Call (RFC) framework lets authenticated attackers bypass key checks and escalate privileges, risking app integrity and availability.
“SAP Security Note #3600840, tagged with a CVSS score of 9.6, patches a critical Missing Authorization Check vulnerability in the Remote Function Call (RFC) framework of SAP NetWeaver Application Server AS ABAP.” reads the report published by security firm Onapsis. “Under certain conditions, authenticated attackers can bypass the standard authorization check on authorization object S_RFC when using transactional (tRFC) or queued RFCs (qRFC), leading to an escalation of privileges. This allows an attacker to critically impact the application’s integrity and availability.”
June 2025 Security Patch Day addressed a total of five high-severity flaws:
- CVE-2025-42982 (CVSS score of 8.8) – Information Disclosure in SAP GRC (AC Plugin)
- CVE-2025-42983 (CVSS score of 8.5) – Missing Authorization check in SAP Business Warehouse and SAP Plug-In Basis
- CVE-2025-23192 (CVSS score of 8.2) – Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence (BI Workspace)
- CVE-2025-42977 (CVSS score of 7.6) – Directory Traversal vulnerability in SAP NetWeaver Visual Composer
- CVE-2025-42994 (CVSS score of 7.5) – Multiple vulnerabilities in SAP MDM Server
The software giant also fixed six other medium-severity issues, and two low-severity bugs.
The advisory published by SAP does not mention any attacks exploiting the above vulnerabilities.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, June 2025 Security Patch Day)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/178851/security/sap-june-2025-security-patch-day-fixed-critical-netweaver-bug.html