Action and evidence
Operational decision
- Action type
- Deploy Patch
- Platform
- SAP
- Restart
- unknown
- Vendor signal
- Low; CVSS 3.5
Why this urgency
- Fix Available
- Routine Review
Evidence signals kept separate
- CISA KEV
- Unknown
- Confirmed exploitation
- Not Stated
- Vendor exploitability
- Not stated in the reviewed source
- Maximum CVSS
- 3.5 (CVSS 3.1, CVE-2025-27430)
- Maximum EPSS
- Not loaded for this patch record
BlackTree recommends the normal approved patch window. No accepted exploitation or emergency signal currently justifies an out-of-band change by itself.
BlackTree urgency is an operational review window. It does not replace vendor severity or CVSS.
Environment override questions
- Is SAP CRM and SAP S/4HANA (Interaction Center), Versions - S4CRM 100, 200, 204, 205, 206, S4FND 102, 103, 104, 105, 106, 107, 108, S4CEXT 107, 108, BBPCRM 701, 702, 712, 713, 714, WEBCUIF 701, 731, 746, 747, 748, 800, 801 exposed to untrusted networks or content?
- Does this update affect an identity, management, backup or other control-plane system?
- Are compensating controls tested and monitored until the selected patch window?
