July’s SAP Patch Day – 27 Vulnerabilities Resolved, 7 Marked Critical

On July 8, 2025, SAP released its monthly Security Patch Day updates, addressing 27 new vulnerabilities across various SAP products and components.

SAP strongly recommends immediate patching to protect enterprise SAP landscapes from potential exploitation.

The patch release includes six critical vulnerabilities with Common Vulnerability Scoring System (CVSS) scores ranging from 9.1 to 10.0.

Critical Vulnerabilities Requiring Immediate Attention

Multiple Live Auction Cockpit Vulnerabilities

The most severe vulnerability, CVE-2025-30012, affects the SAP Supplier Relationship Management Live Auction Cockpit with a perfect CVSS score of 10.0.

This vulnerability represents an update to Security Note 3578900 from May 2025, addressing multiple vulnerabilities including CVE-2025-30009, CVE-2025-30010, CVE-2025-30011, and CVE-2025-30018.

The Live Auction Cockpit uses a deprecated Java applet component that accepts binary Java objects in a specific encoding format, allowing unauthenticated attackers to send malicious payload requests that result in the deserialization of data and potential arbitrary OS command execution.

Code Injection in SAP S/4HANA and SCM

CVE-2025-42967 presents a critical code injection vulnerability in SAP S/4HANA and SAP SCM Characteristic Propagation systems with a CVSS score of 9.1.

This vulnerability allows attackers with high privileges to create new reports with malicious code, potentially gaining full control of the affected SAP system and causing high impact on confidentiality, integrity, and availability.

Widespread Java Deserialization Vulnerabilities

The July patch day addresses multiple critical Java deserialization vulnerabilities across SAP NetWeaver Enterprise Portal and related components.

CVE-2025-42980 affects the SAP NetWeaver Enterprise Portal Federated Portal Network, while CVE-2025-42964 impacts the SAP NetWeaver Enterprise Portal Administration component.

CVE-2025-42966 addresses unsafe Java deserialization in the SAP NetWeaver XML Data Archiving Service, and CVE-2025-42963 affects the SAP NetWeaver Application Server for Java Log Viewer.

All these vulnerabilities carry CVSS scores of 9.1, indicating their critical nature.

Understanding CVSS Scoring

The Common Vulnerability Scoring System (CVSS) provides a standardized method for rating the severity of security vulnerabilities, with scores ranging from 0 to 10.

SAP has been using CVSS since 2016 to communicate vulnerability severity in its security notes, focusing on the Base metric group, which represents the intrinsic characteristics of vulnerabilities.

The CVSS framework consists of three metric groups: Base, Temporal, and Environmental, with SAP primarily utilizing Base scores to provide consistent severity ratings across its product portfolio.

According to SAP’s implementation, vulnerabilities are classified as Critical (CVSS 9.0-10.0), High (CVSS 7.0-8.9), Medium (CVSS 4.0-6.9), and Low (CVSS 0.1-3.9).

The adoption of CVSS version 3.0 has resulted in generally higher scores compared to previous versions, providinga better indication of relative severity.

Enterprise Impact and Mitigation Strategies

The July 2025 patch day vulnerabilities pose significant risks to enterprise SAP environments.

Missing authorization checks, which represent a substantial portion of SAP security vulnerabilities, can allow unauthorized users to access critical business functions and perform actions they should not be able to accomplish.

These vulnerabilities can lead to data breaches, sensitive information loss, and financial losses.

Java deserialization vulnerabilities are particularly dangerous as they can enable remote code execution, allowing attackers to gain full control over SAP systems.

The presence of multiple deserialization vulnerabilities in Enterprise Portal components suggests a systematic security concern that requires immediate attention.

Organizations should implement comprehensive patch management processes to keep SAP systems protected and up-to-date with security patches.

Third-party security solutions can help scan customer code bases for vulnerabilities and provide automated patch deployment capabilities.

Organizations must maintain visibility across their SAP landscape and implement proper change management processes for security updates.

SAP continues to emphasize the importance of visiting the Support Portal and applying patches with priority to protect SAP landscapes from potential exploitation.

The monthly Security Patch Day schedule, released on the second Tuesday of each month, provides predictable timing for organizations to plan their security maintenance activities.

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories