Skip to content
SAP Patch Day brings 18 new security advisories

SAP Patch Day brings 18 new security advisories

Heise.De November 11, 2025

SAP held its monthly patch day on Tuesday and released 18 new security advisories. Two of these address security flaws that the Walldorf-based developers classify as critical security risks; one even reaches the maximum CVSS score of 10.

The overview page for the November Patch Day lists SAP lists the affected products with a brief vulnerability description. In SQL Anywhere Monitor (Non-GUI), there is a vulnerability concerning insecure management of keys and secrets (CVE-2025-42890, CVSS 10.0 , Risk “ critical ”). The CVE entry specifies that credentials are hardcoded in the code, which can ultimately lead to the execution of injected malicious code.

Furthermore, authenticated attackers can inject malicious code into SAP Solution Manager (CVE-2025-42887, CVSS 9.9 , Risk “ critical ”). According to the description attributes this to missing input validation and filtering. This is achieved when calling a function module from the network and leads to elevated access rights, with which attackers can take full control of the system. Finally, SAP CommonCryptoLib has a memory access vulnerability (CVE-2025-42940, CVSS 7.5 , Risk “ high ”). With manipulated packets, attackers can cause a software crash and thus a denial-of-service, explains the vulnerability description .

The other security advisories address vulnerabilities that are less severe. Admins should nevertheless check if they are running vulnerable instances and install the updates during the maintenance window.

The Patch day from SAP in October was noticeably less extensive, with 13 security advisories. Of the security vulnerabilities, the developers classified three as critical.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.