SAP Security Patch Day: A Comedy of Bugs and Fixes for 2025!
SAP’s February 2025 Patch Day arrives with a whopping 19 new and two updated security notes. Highlights include high-priority patches for BusinessObjects, NetWeaver, and others. The most severe bug, CVE-2025-0064, allows attackers to impersonate users. SAP advises quick implementation of these fixes to stay ahead of potential cyber shenanigans.

Hot Take:
Looks like SAP is throwing a cybersecurity party and everyone’s invited—except the hackers, of course. With 19 new and two updated security notes, they’re patching more holes than a ship in a stormy sea. But hey, at least they’re making sure the ship doesn’t sink, right?
Key Points:
- SAP released 19 new and two updated security notes in February 2025.
- Six of these notes, including five new and one update, are high priority.
- Critical vulnerabilities addressed include improper authorization, path traversal, and authentication bypass.
- The most severe vulnerability, with a CVSS score of 8.7, affects BusinessObjects.
- Organizations are advised to apply the patches promptly to prevent potential exploitation.
Already a member? Log in here