SAP Security Patch Day - 2025.09

2025๋…„ 9์›” 9์ผ, SAP Security Patch Day ์— 21๊ฐœ์˜ ์ƒˆ๋กœ์šด Security Notes ์™€ 5๊ฐœ์˜ ์—…๋ฐ์ดํŠธ Security Notes, ์ด 26๊ฐœ์˜ ๋ณด์•ˆ ๋…ธ์ธ ๊ฐ€ ์ถœ์‹œ๋˜์—ˆ๋‹ค.

๊ทธ๋ฆฌ๊ณ  ์ดํ›„, 2๊ฐœ์˜ ์—…๋ฐ์ดํŠธ Security Notes ๊ฐ€ ์ถ”๊ฐ€ ์ถœ์‹œ๋˜์—ˆ๋‹ค.



1. OverView


= ์ „์ฒด ๋ณด์•ˆ ๋…ธ์ธ  ๊ฑด์ˆ˜ : 26๊ฑด

๐Ÿ”ด HotNews/ Critical ย : 4๊ฑด
๐ŸŸ  High Priority ย ย ย ย โ€‚โ€‚: 4๊ฑด
๐ŸŸก Medium Priority ย ย : 15๊ฑด
โšช Low Priority ย ย โ€‚โ€‚โ€‚โ€‚: 3๊ฑด


= ์ „์ฒด ์š”์•ฝ

์ด๋ฒˆ ๋‹ฌ์—๋Š” ์น˜๋ช…์ ์ธ ์šฐ์„ ์ˆœ์œ„(Critical) 4๊ฐœ, ๋†’์€ ์šฐ์„ ์ˆœ์œ„๊ฐ€ 4๊ฐœ, ์ค‘๊ฐ„ ์šฐ์„ ์ˆœ์œ„์— 15๊ฐœ์˜ Notes ๋“ฑ, ์ด 26๊ฐœ์˜ ๋ณด์•ˆ ํŒจ์น˜๋ฅผ ์„ ๋ณด์˜€๋‹ค.

์น˜๋ช…์ /๋†’์€ ์šฐ์„ ์ˆœ์œ„์˜ ๋ณด์•ˆ ํŒจ์น˜์—๋Š” ์—ญ์ง๋ ฌํ™”, ์›น ์„œ๋น„์Šค ๊ฒฐํ•จ, ๋””๋ ‰ํ„ฐ๋ฆฌ ํƒ์ƒ‰ ์ทจ์•ฝ์ , ๊ถŒํ•œ ๊ฒ€์‚ฌ ๋ˆ„๋ฝ ๋“ฑ ๋‹ค์–‘ํ•œ ์ทจ์•ฝ์ ๋“ค์— ๋Œ€ํ•ด์„œ ๋‹ค๋ฃจ๊ณ  ์žˆ๋‹ค.

ํŠนํžˆ, ์—ญ์ง๋ ฌํ™”์™€ ๋””๋ ‰ํ„ฐ๋ฆฌ ํƒ์ƒ‰ ์ทจ์•ฝ์ ์€ ๋ช‡๋‹ฌ ์ „๋ถ€ํ„ฐ ๊ณ„์† ์ถœ์‹œ๋˜๊ณ  ์žˆ๊ณ , ๊ถŒํ•œ ์ ๊ฒ€ ๋ˆ„๋ฝ์˜ ๊ฒฝ์šฐ๋„ ์ง€์†ํ•ด์„œ ์‹ ๊ทœ ์˜ค๋ธŒ์ ํŠธ์— ๋Œ€ํ•œ ๋ณด์•ˆ Notes ๊ฐ€ ์ถœ์‹œ๋˜๊ณ  ์žˆ์œผ๋‹ˆ, 9์›” ์ด์ „ ๊ณต๊ฐœ๋œ ๋ณด์•ˆ ๋‰ด์Šค๋„ ๊ผผ๊ผผํžˆ ์‚ดํŽด๋ณด๊ธธ ๋ฐ”๋ž€๋‹ค.

์ค‘๊ฐ„ ์šฐ์„ ์ˆœ์œ„์—์„œ๋„ ๋งŽ์€ Security Notes ๋“ค์ด ์ถœ์‹œ๋˜์—ˆ๋Š”๋ฐ, ๊ถŒํ•œ ์ ๊ฒ€ ๋ˆ„๋ฝ, XSS ์ทจ์•ฝ์  ๋“ฑ๋“ฑ์ด ์žˆ๋‹ค.



2. Important News

๐Ÿ”ด 2-1. 3634501 - [CVE-2025-42944] Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)

๐Ÿ”ฐ Notes Release : 2025.09.12 (Version 38)

๐Ÿ”ฐ CVSS Base Vector : 10.0 (์น˜๋ช…์ )

โœ… ์š”์•ฝ

SAP NetWeaver ์˜ ์—ญ์ง๋ ฌํ™”(Deserialization) ์ทจ์•ฝ์ ์œผ๋กœ ์ธํ•ด ์ธ์ฆ๋˜์ง€ ์•Š์€ ๊ณต๊ฒฉ์ž๊ฐ€ RMI-P4 ๋ชจ๋“ˆ์„ ํ†ตํ•ด ์˜คํ”ˆ๋œ ํฌํŠธ์— ์•…์„ฑ ํŽ˜์ด๋กœ๋“œ๋ฅผ ์ œ์ถœํ•˜์—ฌ ์‹œ์Šคํ…œ์„ ์•…์šฉํ•  ์ˆ˜ ์žˆ์Œ.
์ด๋Ÿฌํ•œ ์—ญ์ง๋ ฌํ™” ์ทจ์•ฝ์  ๊ณต๊ฒฉ์œผ๋กœ ์ž„์˜์˜ OS ๋ช…๋ น ์‹คํ–‰์œผ๋กœ ์ด์–ด์งˆ ์ˆ˜ ์žˆ์Œ.

โ€ป FAQ ๋ฌธ์„œ

  • SAP Notes 3637718 - FAQ for SAP Security Note 3634501 - [CVE-2025-42944] Parsing/Deserialization issues vulnerability in RMI-P4

FAQ ๋ฌธ์„œ Q1 ์— ๋”ฐ๋ฅด๋ฉด, ๋ชจ๋“  ๋ฆด๋ฆฌ์ฆˆ์˜ Netweaver AS Java, Netweaver ์Šคํƒ์ด ์˜ํ–ฅ์„ ๋ฐ›๋Š”๋‹ค๊ณ  ํ•œ๋‹ค. (EP, PO ๋“ฑ๋“ฑ)

(10.14 ์—…๋ฐ์ดํŠธ)
์•„๋ž˜ SAP Notes ๋ฅผ ํ†ตํ•ด์„œ, As JAVA ์‹œ์Šคํ…œ์˜ ์—ญ์ง๋ ฌํ™”์— ๋Œ€ํ•œ ์ž„์‹œ ๋ณด์•ˆ๊ฐ•ํ™”๊ฐ€ ๊ฐ€๋Šฅํ•ด์กŒ๋‹ค.

  • SAP Notes 3660659 - [CVE-2025-42944] Security Hardening for Insecure Deserialization in SAP NetWeaver AS Java

โœ… ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ์˜ํ–ฅ๋„

์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๊ธฐ๋ฐ€์„ฑ, ๋ฌด๊ฒฐ์„ฑ ๋ฐ ๊ฐ€์šฉ์„ฑ์— ๋งค์šฐ ๋†’์€ ์˜ํ–ฅ

โœ… ์‚ฌ์œ  ๋ฐ ์„ ํ–‰์กฐ๊ฑด

์‹ ๋ขฐํ•  ์ˆ˜ ์—†๊ฑฐ๋‚˜, ์•…์˜์ ์ธ ์ปจํ…์ธ ์˜ ์•ˆ์ „ํ•˜์ง€ ์•Š์€ ์—ญ์ง๋ ฌํ™”

โœ… ์š”์•ฝ ํ•ด๊ฒฐ์ฑ…

โ—พ SERVERCORE 7.50 ์„œํฌํŠธ ํŒจํ‚ค์ง€(SP) ํŒจ์น˜

โ—พ (Workaround) (์ „์ œ์กฐ๊ฑด : ๋„คํŠธ์›Œํฌ๊ฐ€ ์•ˆ์ „ํ•œ ์ˆ˜์ค€์—์„œ ๊ฒฉ๋ฆฌ๋˜์–ด์žˆ๋Š” ํ™˜๊ฒฝ)
P4/P4S ํฌํŠธ์— ์•ˆ์ „ํ•œ ๋‚ด๋ถ€ ๋„คํŠธ์›Œํฌ IP ๋งŒ ์ˆ˜์‹ ๋˜๋„๋ก ์ˆ˜์ •(ACL ์„ค์ •).
โ€ป ๋‹จ, ACL ํŒŒ์ผ์ด ์กด์žฌํ•˜์ง€ ์•Š๊ฑฐ๋‚˜, ๊ตฌ๋ฌธ์ด ๋ถ€์ •ํ™•ํ•˜๋ฉด ICM ์ด ์ค‘์ง€๋จ.
โ€ป ๋˜ํ•œ FAQ Notes Q8. ์— ๋”ฐ๋ฅธ ๋ถ€์ž‘์šฉ์ด ์žˆ์„ ์ˆ˜ ์žˆ์Œ.

  • ACL File ์˜ต์…˜ ์ถ”๊ฐ€ (icm/server_port_0 ํŒŒ๋ผ๋ฏธํ„ฐ ์˜ˆ์‹œ)
    : PROT=P4,PORT=5$(SAPSYSTEM)04,TIMEOUT=300,ACLFILE=<ACL File ๊ฒฝ๋กœ>

  • ACL File ๊ตฌ๋ฌธ ์˜ˆ์‹œ
(Syntax) 
<permit | deny> <ip-address[/mask]> [tracelevel] [# comment]
_____________________________________________________________________________
permit 10.1.2.0/24          # permit client network
permit 192.168.7.0/24       # permit server network
permit 10.0.0.0/8 1         # screening rule (learning mode, trace-level 1)
permit 2001:db8::1428:57ab  # permit IPv6 host
deny   0.0.0.0/0            # ๋ช…์‹œ์ ์œผ๋กœ permit IP ๋ฅผ ์ œ์™ธํ•œ ๋ชจ๋“  ๊ทœ์น™ ์ฐจ๋‹จ
_____________________________________________________________________________
  • FAQ Q8. ์— ๋”ฐ๋ฅด๋ฉด, P4/P4S ํฌํŠธ๋Š” Enterprise Services Repository(ESR), Integration Builder(IB) ํˆด์˜ ์ ‘์† ๋ฐ ์ˆ˜ํ–‰์— ์‚ฌ์šฉ๋˜๋ฉฐ, ํ•ด๋‹น ๋„๊ตฌ์˜ ์‚ฌ์šฉ ์ œํ•œ(ACL ์„ค๊ณ„์— ๋”ฐ๋ผ) ์™ธ์— PI/PO ์‹œ์Šคํ…œ์˜ ๋Ÿฐํƒ€์ž„ ์ž‘์—…์—๋Š” ์˜ํ–ฅ์„ ๋ฏธ์น˜์ง€ ์•Š๋Š”๋‹ค๊ณ  ์„ค๋ช…ํ•œ๋‹ค.

โœ… ์†Œํ”„ํŠธ์›จ์–ด ์ปดํฌ๋„ŒํŠธ

โ—พ J2EE ENGINE SERVERCORE 7.50 ALL SP.


๐Ÿ”ด 2-2. 3643865 - [CVE-2025-42922] Insecure File Operations vulnerability in SAP NetWeaver AS Java (Deploy Web Service)

๐Ÿ”ฐ Notes Release : 2025.09.10 (Version 13)

๐Ÿ”ฐ CVSS Base Vector : 9.9 (์น˜๋ช…์ )

โœ… ์š”์•ฝ

SAP NetWeaver AS Java ๋Š” ์ผ๋ฐ˜ ์‚ฌ์šฉ์ž๋กœ ์ธ์ฆ๋œ ๊ณต๊ฒฉ์ž๊ฐ€ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์„œ๋น„์Šค์˜ ๊ฒฐํ•จ์„ ์ด์šฉํ•˜์—ฌ ์ž„์˜์˜ ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•  ์ˆ˜ ์žˆ๋„๋ก ํ—ˆ์šฉํ•จ.

โ€ป FAQ ๋ฌธ์„œ

  • SAP Notes 3646072 - FAQ for SAP Security Note 3643865 - [CVE-2025-42922] Insecure File Operations vulnerability in SAP NetWeaver AS Java (Deploy Web service)

โœ… ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ์˜ํ–ฅ๋„

์‹œ์Šคํ…œ์˜ ๊ธฐ๋ฐ€์„ฑ, ๋ฌด๊ฒฐ์„ฑ ๋ฐ ๊ฐ€์šฉ์„ฑ์— ๋งค์šฐ ๋†’์€ ์˜ํ–ฅ

โœ… ์‚ฌ์œ  ๋ฐ ์„ ํ–‰์กฐ๊ฑด

Deploy Web Service ๊ฒฐํ•จ

โœ… ์š”์•ฝ ํ•ด๊ฒฐ์ฑ…

โ—พ J2EE-APPS 7.50 ์„œํฌํŠธ ํŒจํ‚ค์ง€(SP) ํŒจ์น˜
โ—พ (Workaround) FAQ Notes Workaruound ์— ๋”ฐ๋ผ Deploy Web Service ๋น„ํ™œ์„ฑํ™”

โœ… ์†Œํ”„ํŠธ์›จ์–ด ์ปดํฌ๋„ŒํŠธ

โ—พ J2EE ENGINE APPLICATIONS 7.50 ALL SP.


๐Ÿ”ด 2-3. 3302162 - [CVE-2023-27500] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

๐Ÿ”ฐ Notes Release : 2025.09.09 (Version 11)

๐Ÿ”ฐ CVSS Base Vector : 9.6 (์น˜๋ช…์ )

โœ… ์š”์•ฝ

SAP Netweaver AS ABAP, ABAP Platform ์—์„œ ๊ด€๋ฆฌ์ž ๊ถŒํ•œ์ด ์—†๋Š” ๊ณต๊ฒฉ์ž๊ฐ€ SAPRSBRO ํ”„๋กœ๊ทธ๋žจ์˜ ๋””๋ ‰ํ„ฐ๋ฆฌ ํƒ์ƒ‰ ์ทจ์•ฝ์ ์„ ์•…์šฉํ•˜์—ฌ ์‹œ์Šคํ…œ ํŒŒ์ผ์„ ๋ฎ์–ด์“ธ ์ˆ˜ ์žˆ์Œ.
์ด ๊ณต๊ฒฉ์œผ๋กœ ๋ฐ์ดํ„ฐ๋ฅผ ์ฝ์„ ์ˆ˜๋Š” ์—†์ง€๋งŒ, ์ค‘์š”ํ•œ OS ํŒŒ์ผ์„ ๋ฎ์–ด์”€์œผ๋กœ์จ ์‹œ์Šคํ…œ์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†๊ฒŒ ๋งŒ๋“ค ์ˆ˜๋„ ์žˆ์Œ.

โ€ป FAQ ๋ฌธ์„œ

  • SAP Notes 3311360 - FAQ for SAP Security Note 3302162

โœ… ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ์˜ํ–ฅ๋„

์‹œ์Šคํ…œ์˜ ๋ฌด๊ฒฐ์„ฑ, ๊ฐ€์šฉ์„ฑ์— ๋งค์šฐ ๋†’์€ ์˜ํ–ฅ

โœ… ์‚ฌ์œ  ๋ฐ ์„ ํ–‰์กฐ๊ฑด

SAPRSBRO ํ”„๋กœ๊ทธ๋žจ์˜ ๋””๋ ‰ํ„ฐ๋ฆฌ ํƒ์ƒ‰ ์ทจ์•ฝ์  ์•…์šฉ

โœ… ์š”์•ฝ ํ•ด๊ฒฐ์ฑ…

โ—พ SAP_BASIS ์„œํฌํŠธ ํŒจํ‚ค์ง€(SP) ํŒจ์น˜
โ—พ Security Notes ์ ์šฉ
โ—พ (Workaround) SAPRSBRO ํ”„๋กœ๊ทธ๋žจ ์ˆ˜ํ–‰ ๊ถŒํ•œ ์ œํ•œ
โ†’ ๊ถŒํ•œ ์˜ค๋ธŒ์ ํŠธ S_PROGNAM / ๊ถŒํ•œ ํ•„๋“œ P_PROGNAM = SAPRSBRO, ๊ถŒํ•œ ํ•„๋“œ P_ACTION = SUBMIT ๊ถŒํ•œ ํšŒ์ˆ˜

โœ… ์†Œํ”„ํŠธ์›จ์–ด ์ปดํฌ๋„ŒํŠธ

โ—พ SAP_BASIS 700 ~ 757


๐Ÿ”ด 2-4. 3627373 - [CVE-2025-42958] Missing Authentication check in SAP NetWeaver

๐Ÿ”ฐ Notes Release : 2025.09.09 (Version 10)

๐Ÿ”ฐ CVSS Base Vector : 9.1 (์น˜๋ช…์ )

โœ… ์š”์•ฝ

IBM i-์‹œ๋ฆฌ์ฆˆ ๊ธฐ๋ฐ˜ SAP NetWeaver ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ์ธ์ฆ ๊ฒ€์‚ฌ ๋ˆ„๋ฝ์œผ๋กœ ์ธํ•ด,
๊ถŒํ•œ์ด ๋†’์€ ๋ฌด๋‹จ ์‚ฌ์šฉ์ž๊ฐ€ ๋ฏผ๊ฐํ•œ ์ •๋ณด๋ฅผ ์ฝ๊ณ , ์ˆ˜์ •ํ•˜๊ณ , ์‚ญ์ œํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ๊ด€๋ฆฌ ๊ธฐ๋Šฅ์ด๋‚˜ ๊ถŒํ•œ์ด ํ•„์š”ํ•œ ๊ธฐ๋Šฅ์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Œ.

โ€ป FAQ ๋ฌธ์„œ

  • SAP Notes 3628734 - FAQ Note for SAP Security Note 3627373

โœ… ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ์˜ํ–ฅ๋„

์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๊ธฐ๋ฐ€์„ฑ, ๋ฌด๊ฒฐ์„ฑ ๋ฐ ๊ฐ€์šฉ์„ฑ์— ๋งค์šฐ ๋†’์€ ์˜ํ–ฅ

โœ… ์‚ฌ์œ  ๋ฐ ์„ ํ–‰์กฐ๊ฑด

(์ „์ œ์กฐ๊ฑด) IBM i OS ์˜ ํ•˜๋‚˜์˜ ๋…ผ๋ฆฌ ํŒŒํ‹ฐ์…˜(LPAR) ์—์„œ SID ๊ฐ€ ์„œ๋กœ ๋‹ค๋ฅธ ๋‘ ๊ฐœ์˜ SAP ์ธ์Šคํ„ด์Šค๊ฐ€ ๊ตฌ์„ฑ๋œ ๊ฒฝ์šฐ์ผ๋•Œ ์˜ํ–ฅ์„ ๋ฐ›์Œ.
(AS400/OS400/IBM i-Series/Power Series)

โœ… ์š”์•ฝ ํ•ด๊ฒฐ์ฑ…

โ—พ SAP Kernel ํŒจ์น˜

โœ… ์†Œํ”„ํŠธ์›จ์–ด ์ปดํฌ๋„ŒํŠธ

โ—พ SAP KERNEL 7.22 ~ 7.54


๐ŸŸ  2-5. 3642961 - [CVE-2025-42933] Insecure Storage of Sensitive Information in SAP Business One (SLD)

๐Ÿ”ฐ Notes Release : 2025.09.08 (Version 8)

๐Ÿ”ฐ CVSS Base Vector : 8.8 (๋†’์Œ)

โœ… ์š”์•ฝ

์‚ฌ์šฉ์ž๊ฐ€ SAP Business One Native Client(๊ธฐ๋ณธ ํด๋ผ์ด์–ธํŠธ) ๋ฅผ ํ†ตํ•ด ๋กœ๊ทธ์ธํ•  ๋•Œ, SLD ๋ฐฑ์—”๋“œ ์„œ๋น„์Šค๊ฐ€ ํŠน์ • API ์— ๋Œ€ํ•ด์„œ ์ ์ ˆํ•œ ์•”ํ˜ธํ™”๋ฅผ ์ˆ˜ํ–‰ํ•˜์ง€ ๋ชปํ•จ.
์ด๋กœ ์ธํ•ด, HTTP ์‘๋‹ต ๋ณธ๋ฌธ ๋‚ด์— ๋ฏผ๊ฐํ•œ ์ž๊ฒฉ ์ฆ๋ช…์ด ๋…ธ์ถœ๋จ.

โœ… ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ์˜ํ–ฅ๋„

์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๊ธฐ๋ฐ€์„ฑ, ๋ฌด๊ฒฐ์„ฑ ๋ฐ ๊ฐ€์šฉ์„ฑ์— ๋†’์€ ์˜ํ–ฅ

โœ… ์‚ฌ์œ  ๋ฐ ์„ ํ–‰์กฐ๊ฑด

SLD ๋ฐฑ์•ค๋“œ ํŠน์ • API ์— ๋Œ€ํ•œ ์•”ํ˜ธํ™” ๋ˆ„๋ฝ

โœ… ์š”์•ฝ ํ•ด๊ฒฐ์ฑ…

โ—พ SAP BUSINESS ONE 10.0 / SAP B1 10.0 FOR SAP HANA ์„œํฌํŠธ ํŒจํ‚ค์ง€(SP) ํŒจ์น˜

โœ… ์†Œํ”„ํŠธ์›จ์–ด ์ปดํฌ๋„ŒํŠธ

โ—พ B1_ON_HANA 10.0
โ—พ SAP-M-BO 10.0


๐ŸŸ  2-6. 3633002 - [CVE-2025-42929] Missing input validation vulnerability in SAP Landscape Transformation Replication Server

๐Ÿ”ฐ Notes Release : 2025.09.09 (Version 8)

๐Ÿ”ฐ CVSS Base Vector : 8.1 (๋†’์Œ)

โœ… ์š”์•ฝ

SAP Landscape Transformation Replication Server ์—์„œ ์ž…๋ ฅ ๊ฒ€์ฆ์ด ๋ˆ„๋ฝ๋˜์–ด ๋†’์€ ๊ถŒํ•œ์„ ๊ฐ€์ง„ ๊ณต๊ฒฉ์ž๊ฐ€ ABAP ๋ฆฌํฌํŠธ๋ฅผ ํ†ตํ•ด, ๊ถŒํ•œ ๊ทธ๋ฃน์œผ๋กœ ๋ณดํ˜ธ๋˜์ง€ ์•Š์€ ํ…Œ์ด๋ธ”์˜ ๋‚ด์šฉ์„ ์ž„์˜๋กœ ์‚ญ์ œํ•  ์ˆ˜ ์žˆ์Œ.

โœ… ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ์˜ํ–ฅ๋„

๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์˜ ๋ฌด๊ฒฐ์„ฑ, ๊ฐ€์šฉ์„ฑ์— ๋†’์€ ์˜ํ–ฅ

โœ… ์‚ฌ์œ  ๋ฐ ์„ ํ–‰์กฐ๊ฑด

๋ถ€์ ์ ˆํ•œ ์ž…๋ ฅ ๊ฒ€์ฆ ๋ฐ ์ฒ˜๋ฆฌ

โœ… ์š”์•ฝ ํ•ด๊ฒฐ์ฑ…

โ—พ DMIS ์„œํฌํŠธ ํŒจํ‚ค์ง€(SP) ํŒจ์น˜
โ—พ Security Notes ์ ์šฉ

โœ… ์†Œํ”„ํŠธ์›จ์–ด ์ปดํฌ๋„ŒํŠธ

โ—พ DMIS 2011_1_620 ~ 2011_1_752 / 2020


๐ŸŸ  2-7. 3635475 - [CVE-2025-42916] Missing input validation vulnerability in SAP S/4HANA (Private Cloud or On-Premise)

๐Ÿ”ฐ Notes Release : 2025.09.08 (Version 5)

๐Ÿ”ฐ CVSS Base Vector : 8.1 (๋†’์Œ)

โœ… ์š”์•ฝ

SAP S/4HANA (Private Cloud or On-Premise) ์—์„œ ์ž…๋ ฅ ๊ฒ€์ฆ์ด ๋ˆ„๋ฝ๋˜์–ด, ๋†’์€ ๊ถŒํ•œ์„ ๊ฐ€์ง„ ๊ณต๊ฒฉ์ž๊ฐ€ ABAP ๋ฆฌํฌํŠธ๋ฅผ ํ†ตํ•ด, ๊ถŒํ•œ ๊ทธ๋ฃน์œผ๋กœ ๋ณดํ˜ธ๋˜์ง€ ์•Š์€ ํ…Œ์ด๋ธ”์˜ ๋‚ด์šฉ์„ ์ž„์˜๋กœ ์‚ญ์ œํ•  ์ˆ˜ ์žˆ์Œ.

โœ… ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ์˜ํ–ฅ๋„

๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์˜ ๋ฌด๊ฒฐ์„ฑ, ๊ฐ€์šฉ์„ฑ์— ๋†’์€ ์˜ํ–ฅ

โœ… ์‚ฌ์œ  ๋ฐ ์„ ํ–‰์กฐ๊ฑด

๋ถ€์ ์ ˆํ•œ ์ž…๋ ฅ ๊ฒ€์ฆ ๋ฐ ์ฒ˜๋ฆฌ

โœ… ์š”์•ฝ ํ•ด๊ฒฐ์ฑ…

โ—พ S4CORE ์„œํฌํŠธ ํŒจํ‚ค์ง€(SP) ํŒจ์น˜
โ—พ Security Notes ์ ์šฉ

โœ… ์†Œํ”„ํŠธ์›จ์–ด ์ปดํฌ๋„ŒํŠธ

โ—พ S4CORE 102 ~ 108


๐ŸŸ  2-8. 3581811 - [CVE-2025-27428] Directory Traversal vulnerability in SAP NetWeaver and ABAP Platform (Service Data Collection)

๐Ÿ”ฐ Notes Release : 2025.09.09 (Version 8)

๐Ÿ”ฐ CVSS Base Vector : 7.7 (๋†’์Œ)

โœ… ์š”์•ฝ

SAP Netweaver, ABAP Platform ์—์„œ ๋””๋ ‰ํ„ฐ๋ฆฌ ํƒ์ƒ‰ ์ทจ์•ฝ์ ์œผ๋กœ ์ธํ•ด,
๊ถŒํ•œ์ด ์žˆ๋Š” ๊ณต๊ฒฉ์ž๋Š” RFC ํ•จ์ˆ˜ ๋ชจ๋“ˆ์„ ํ†ตํ•ด ์ผ๋ถ€ ์ค‘์š” ์ •๋ณด์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Œ.
๊ณต๊ฒฉ์— ์„ฑ๊ณตํ•˜๋ฉด SAP Solution Manager ์— ์—ฐ๊ฒฐ๋œ ๋ชจ๋“  ๊ด€๋ฆฌ ์‹œ์Šคํ…œ์˜ ํŒŒ์ผ์„ ์ฝ์„ ์ˆ˜ ์žˆ์Œ.

โœ… ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ์˜ํ–ฅ๋„

์‹œ์Šคํ…œ์˜ ๋ฌด๊ฒฐ์„ฑ, ๊ฐ€์šฉ์„ฑ์— ๋†’์€ ์˜ํ–ฅ

โœ… ์‚ฌ์œ  ๋ฐ ์„ ํ–‰์กฐ๊ฑด

(์ „์ œ์กฐ๊ฑด) ๊ถŒํ•œ์ด <sid>adm ์‚ฌ์šฉ์ž๋กœ ์„ค์ •๋˜์–ด ์žˆ๊ณ , ์•Œ๋ ค์ง„ '์ ‘๋‘์‚ฌ' ๊ฒฝ๋กœ๋ฅผ ๊ฐ€์ง„ ํŒŒ์ผ ์ด๋ฆ„์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ์Œ.

โœ… ์š”์•ฝ ํ•ด๊ฒฐ์ฑ…

โ—พ ST-PI ์„œํฌํŠธ ํŒจํ‚ค์ง€(SP) ํŒจ์น˜
โ—พ Security Notes ์ ์šฉ

โœ… ์†Œํ”„ํŠธ์›จ์–ด ์ปดํฌ๋„ŒํŠธ

โ—พ ST-PI 2008_1_700 ~ 2008_1_710 / 740



3. Other Priority

ํ•ด๋‹น ๋ถ€๋ถ„์€ ๋†’์€ ์šฐ์„ ์ˆœ์œ„ ๋Š” ์•„๋‹ˆ์ง€๋งŒ, ๋Œ€๋ถ€๋ถ„์˜ ํ™˜๊ฒฝ์—์„œ ๋งŽ์ด ์“ฐ์ด๋Š” ์ปดํฌ๋„ŒํŠธ๋“ค์— ๋Œ€ํ•œ Security Notes๋ฅผ ์ •๋ฆฌํ–ˆ์œผ๋ฉฐ, ์ˆœ์„œ๋Š” CVSS Base Vector ์ ์ˆ˜ ์ˆœ์ด๋‹ค.
๐ŸŸก Medium Priority
โšช Low Priority

๐ŸŸก 3-1. 3629325 - [CVE-2025-42938] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform

๐ŸŸก 3-2. 3619465 - [CVE-2025-42926] Missing Authentication check in SAP NetWeaver Application Server Java

๐ŸŸก 3-3. 3629871 - [CVE-2025-42948] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform

๐ŸŸก 3-4. 3627644 - [CVE-2025-42911] Missing Authorization check in SAP NetWeaver (Service Data Download)

๐ŸŸก 3-5. 3610322 - [CVE-2025-42961] Missing Authorization check in SAP NetWeaver Application Server for ABAP

๐ŸŸก 3-6. 3640477 - [CVE-2025-42925] Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)

๐ŸŸก 3-7. 3623504 - [CVE-2025-42918] Missing Authorization check in SAP NetWeaver Application Server for ABAP (Background Processing)

๐ŸŸก 3-8. 3577131 - [CVE-2025-31331] Authorization Bypass vulnerability in SAP NetWeaver

โšช 3-9. 3624943 - [CVE-2025-42941] Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad)

โšช 3-10. 3525295 - [CVE-2025-42927] Information Disclosure due to Outdated OpenSSL Version in SAP NetWeaver AS Java (Adobe Document Service)



0๊ฐœ์˜ ๋Œ“๊ธ€