SAP has issued new security patches for 19 vulnerabilities and updated 2 previous Security Notes. This Patch Day features fixes for various issues, including a high-risk authorization flaw in SAP BusinessObjects Business Intelligence.
The critical vulnerability (CVE-2025-0064, CVSS 8.7) enables an attacker with admin rights to impersonate any user in the SAP BusinessObjects Business Intelligence platform, risking sensitive data and system integrity. SAP advises customers to prioritize patching this issue to safeguard their systems.
By infosecbulletin
/ Friday , May 9 2025
Microsoft has fixed critical vulnerabilities in its core cloud services, including Azure Automation, Azure Storage, Azure DevOps, and Microsoft Power...
Read More
By infosecbulletin
/ Thursday , May 8 2025
The cyber threat landscape is rapidly changing, with a notable increase in ransomware activity in April 2025, driven by the...
Read More
By infosecbulletin
/ Thursday , May 8 2025
SonicWall has released patches for three security flaws in SMA 100 Secure Mobile Access appliances that could allow remote code...
Read More
By infosecbulletin
/ Thursday , May 8 2025
From April 2024 to April 2025, Flashpoint analysts noted that the financial sector was a major target for threat actors,...
Read More
By infosecbulletin
/ Thursday , May 8 2025
Cisco has issued a security advisory for a critical vulnerability in its IOS XE Software for Wireless LAN Controllers (WLCs)....
Read More
By infosecbulletin
/ Wednesday , May 7 2025
Attackers linked to the Play ransomware operation deployed a zero-day privilege escalation exploit during an attempted attack against an organization...
Read More
By infosecbulletin
/ Wednesday , May 7 2025
Hackers are exploiting an unauthenticated remote code execution vulnerability in the Samsung MagicINFO 9 Server to take control of devices...
Read More
By infosecbulletin
/ Tuesday , May 6 2025
CISA added the Langflow vulnerability, CVE-2025-3248 (CVSS score 9.8), to its Known Exploited Vulnerabilities catalog. Langflow is a popular tool...
Read More
By infosecbulletin
/ Tuesday , May 6 2025
Google has released its monthly Android security updates, addressing 46 vulnerabilities, including one that has been actively exploited. CVE-2025-27363 (CVSS...
Read More
By infosecbulletin
/ Tuesday , May 6 2025
The Cyber Security Club, representing the Department of Computer Science and Engineering at the University of Asia Pacific (UAP), has...
Read More
Other high-severity vulnerabilities addressed in this Patch Day include:
Path Traversal Vulnerability in SAP Supplier Relationship Management (CVE-2025-25243, CVSS 8.6): This flaw lets an unauthorized user access and download sensitive files.
Authentication Bypass in SAP Approuter (CVE-2025-24876, CVSS 8.1): This vulnerability allows attackers to steal user sessions and access applications without authorization.
SAP Enterprise Project Connection has several vulnerabilities (CVE-2024-38819, CVE-2024-38820, CVE-2024-38828) that could let attackers access project data and disrupt operations. SAP also updated two previous Security Notes to enhance protection against potential attacks.
SAP advises customers to review and promptly apply the latest Security Notes and patches. Prioritizing critical vulnerability patching is essential to reduce exploitation risks. Customers should also subscribe to the Security Notification Service for timely alerts on new vulnerabilities and patches.
Akira Topped January 2025 as the Most Active Ransomware Threat