SAP issues monthly Security Patch Day Bulletins on the second Tuesday of every month- which has been synchronized with the Security Patch Day of other major software vendors. This month’s bulletin was issued on July 14, 2026, and contains 16 new security notes. Thankfully, NONE of these notes apply to the SAP BusinessObjects Platform.
However, SAP BusinessObjects customers should be aware that Microsoft is releasing a large number of Windows updates today, including those that will close the chapter on RC4 encryption of Kerberos, which caused a moment of panic for SAP BusinessObjects organizations that still were using RC4 in their encryption settings. Microsoft typically updates their MSRC Security Update Guide around 10 AM Pacific Time today (or any Patch Tuesday).
SAP Knowledge Base Articles worth Sharing
Below are some SAP knowledge base articles worth downloading periodically and sharing with your SAP BusinessObjects and security teams. Hyperlinks are provided to specific KB articles regarding specific CVE.
BI 4.2 / 4.3 / 2025 / 2027 – Fixed CVE and Vulnerabilities List
SAP maintains a comprehensive list of fixed vulnerabilities by version and support pack in SAP KB 3069036 – BI 4.2 / 4.3 / 2025 / 2027 – Fixed CVE and Vulnerabilities List.
Apache Tomcat vulnerabilities NOT impacting SAP BI Platform
When your organization’s security team identifies vulnerabilities in Apache Tomcat, you’ll want to review SAP Note 2498770 – Tomcat vulnerabilities (CVE-*) NOT impacting SAP BI Platform (last updated yesterday, July 13, 2026) to provide documentation that patching is not needed for the SAP BI Platform.
Third-party software vulnerabilities NOT impacting SAP BusinessObjects
The SAP BusinessObjects platform uses multiple third-party software products. In addition to the list above for Apache Tomcat, review SAP Note 2914574 – Third-party software vulnerabilities (CVE) NOT impacting SAP BusinessObjects (last updated today, July 14, 2026) to provide documentation that a patch is not needed for the SAP BI Platform.
SAP JVM Vulnerabilities (CVE) NOT impacting SAP BI Platform
SAP uses its own JVM on the server side, not Oracle’s. SAP Note 2474924 – SAP JVM Vulnerabilities (CVE) NOT impacting SAP BI Platform shares which CVE have been determined to have no impact on the SAP BusinessObjects platform.
Recommendation
Although there are no new vulnerabilities disclosed this month, InfoSol recommends patching to either BI 4.3 SP5 Patch 6 (Patch 7 was released last week) and higher or BI 2025 SP0 Patch 9 (Patch 12 was released last week) and higher for any SAP BusinessObjects customer operating below those patch levels. As always, review SAP’s release notes and patch upgrade guide, which are available on the SAP Help Portal.
Whether you choose BI 4.3 or BI 2025 will largely be determined by whether your organization still uses “classic” UNV universes. These universes are no longer supported in BI 2025 and must be converted to UNX format prior to upgrading to BI 2025. Choosing BI 4.3 or BI 2025 also depends on the age of your hardware and operating system, as many organizations adopting BI 2025 will likely want to deploy it on new hardware using the latest supported version of Windows Server.
IMPORTANT: Support packs prior to BI 4.3 SP5 are no longer under patch support. Customers on BI 4.3 SP4 and earlier (this includes SAP BusinessObjects BI 4.2) should consider patching, as earlier versions are affected by security vulnerabilities.
IMPORTANT: InfoSol does not recommend BI 4.3 SP5 Patch 4 or BI 2025 SP0 Patch 8, as these patch levels were affected by a CMS clustering issue described in SAP Note 3724948.
InfoBurst
InfoSol also recommends that its InfoBurst customers use this opportunity to upgrade to InfoBurst 2026.2. InfoBurst software can be downloaded from the InfoSol Help Portal.
Previous SAP Security articles from Speak BO
How InfoSol Can Help
Don’t wait for security gaps to become business problems. With July’s SAP Security Patch Day and a successful IBIS conference behind us, now is the time to take a smarter, more proactive approach to your BusinessObjects landscape. InfoSol can help you evaluate risk, simplify patching, and align your environment with SAP’s roadmap—from BI 4.x stabilization to BI 2025 and UNX adoption to BI 2027 planning. Let’s make every update a step toward a stronger, more future-ready platform.
Contact InfoSol today to schedule a free patching assessment or upgrade consultation—and ensure your BI environment stays protected, optimized, and compliant.
