March 2025 Patch Tuesday3552144Normal patch window
SAP · 3552144
Assess and apply SAP security advisory 3552144
SAP lists 3552144 in its 2025-03 Security Patch Day release for SAP Business Warehouse (Process Chains), Version – DW4CORE 100, DW4CORE 200, DW4CORE 300, DW4CORE 400, DW4CORE 914, SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 750. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.
- Product
- SAP Business Warehouse (Process Chains), Version – DW4CORE 100, DW4CORE 200, DW4CORE 300, DW4CORE 400, DW4CORE 914, SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 750
- Release
- DW4CORE 100, DW4CORE 200, DW4CORE 300, DW4CORE 400, DW4CORE 914, SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 750
- Published
- 2025-03-11
- Updated
- 2025-03-11
Normal patch windowBlackTree recommended timingmedium confidence
1Vendor-linked CVEsComplete For Public Bulletin
1Preserved revisionsCanonical history remains visible
0Known issuesVendor-documented context only
Action and evidence
Operational decision
- Action type
- Deploy Patch
- Platform
- SAP
- Restart
- unknown
- Vendor signal
- Medium; CVSS 5.7
Why this urgency
- Fix Available
- Routine Review
Evidence signals kept separate
- CISA KEV
- Unknown
- Confirmed exploitation
- Not Stated
- Vendor exploitability
- Not stated in the reviewed source
- Maximum CVSS
- 5.7 (CVSS 3.1, CVE-2025-25244)
- Maximum EPSS
- Not loaded for this patch record
Normal patch windowBlackTree recommends the normal approved patch window. No accepted exploitation or emergency signal currently justifies an out-of-band change by itself.
BlackTree urgency is an operational review window. It does not replace vendor severity or CVSS.
Environment override questions
- Is SAP Business Warehouse (Process Chains), Version – DW4CORE 100, DW4CORE 200, DW4CORE 300, DW4CORE 400, DW4CORE 914, SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 750 exposed to untrusted networks or content?
- Does this update affect an identity, management, backup or other control-plane system?
- Are compensating controls tested and monitored until the selected patch window?
Deployment context
Effects and caveats
- Confirm the installed SAP component and version before applying the correction.
- Use entitled SAP Note content for prerequisites, correction instructions and rollback planning.
Known data gaps
- Authenticated SAP correction content is not copied into the public catalogue.
- Restart and downtime requirements require review of the entitled SAP Note.
Deployment plan
Guidance basis: Mixed
Prerequisites
- Confirm the affected product, edition, architecture and current build before deployment.
Sequencing
- Review the entitled SAP Note and apply prerequisites in the vendor-stated order.
Downtime
Downtime and restart impact are not fully stated in the reviewed public source.
Rollback and recovery
- Capture the current version and a recoverable backup or snapshot before the change.
- Use the vendor-supported uninstall or recovery path when one is available.
Workarounds
- No vendor workaround is asserted unless it appears in the official advisory.
Provenance
Field verification
- Note_identity_product_and_versionssap-patch-day/tableVerified Automatic · Retrieved 26 Aug 2026, 11:55 UTC
- Cve_relationships_and_vendor_signalsap-patch-day/tableVerified Automatic · Retrieved 26 Aug 2026, 11:55 UTC
Open official vendor sourceRevision history
Canonical record changes
- Revision 12025-03-11
Captured from the scheduled SAP Security Patch Day bulletin.
Publication review
The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner approved automatic Patch Tuesday publication. Each published record passed its own official-source completeness gate. Pending sources expose readiness only and prior approved records are retained on refresh failure.