SAP Security Patch Day – July 2026

SAP issues monthly Security Patch Day Bulletins on the second Tuesday of every month- which has been synchronized with the Security Patch Day of other major software vendors. This month’s bulletin was issued on July 14, 2026, and contains 16 new security notes. Thankfully, NONE of these notes apply to the SAP BusinessObjects Platform.

However, SAP BusinessObjects customers should be aware that Microsoft is releasing a large number of Windows updates today, including those that will close the chapter on RC4 encryption of Kerberos, which caused a moment of panic for SAP BusinessObjects organizations that still were using RC4 in their encryption settings. Microsoft typically updates their MSRC Security Update Guide around 10 AM Pacific Time today (or any Patch Tuesday).

SAP Knowledge Base Articles worth Sharing

Below are some SAP knowledge base articles worth downloading periodically and sharing with your SAP BusinessObjects and security teams. Hyperlinks are provided to specific KB articles regarding specific CVE.

BI 4.2 / 4.3 / 2025 / 2027 – Fixed CVE and Vulnerabilities List

SAP maintains a comprehensive list of fixed vulnerabilities by version and support pack in SAP KB 3069036 – BI 4.2 / 4.3 / 2025 / 2027 – Fixed CVE and Vulnerabilities List.

Apache Tomcat vulnerabilities NOT impacting SAP BI Platform

When your organization’s security team identifies vulnerabilities in Apache Tomcat, you’ll want to review SAP Note 2498770Tomcat vulnerabilities (CVE-*) NOT impacting SAP BI Platform (last updated yesterday, July 13, 2026) to provide documentation that patching is not needed for the SAP BI Platform.

Third-party software vulnerabilities NOT impacting SAP BusinessObjects

The SAP BusinessObjects platform uses multiple third-party software products. In addition to the list above for Apache Tomcat, review SAP Note 2914574 – Third-party software vulnerabilities (CVE) NOT impacting SAP BusinessObjects (last updated today, July 14, 2026) to provide documentation that a patch is not needed for the SAP BI Platform.

SAP JVM Vulnerabilities (CVE) NOT impacting SAP BI Platform

SAP uses its own JVM on the server side, not Oracle’s. SAP Note 2474924SAP JVM Vulnerabilities (CVE) NOT impacting SAP BI Platform shares which CVE have been determined to have no impact on the SAP BusinessObjects platform.

Recommendation

Although there are no new vulnerabilities disclosed this month, InfoSol recommends patching to either BI 4.3 SP5 Patch 6 (Patch 7 was released last week) and higher or BI 2025 SP0 Patch 9 (Patch 12 was released last week) and higher for any SAP BusinessObjects customer operating below those patch levels. As always, review SAP’s release notes and patch upgrade guide, which are available on the SAP Help Portal.

Whether you choose BI 4.3 or BI 2025 will largely be determined by whether your organization still uses “classic” UNV universes. These universes are no longer supported in BI 2025 and must be converted to UNX format prior to upgrading to BI 2025. Choosing BI 4.3 or BI 2025 also depends on the age of your hardware and operating system, as many organizations adopting BI 2025 will likely want to deploy it on new hardware using the latest supported version of Windows Server.

IMPORTANT: Support packs prior to BI 4.3 SP5 are no longer under patch support. Customers on BI 4.3 SP4 and earlier (this includes SAP BusinessObjects BI 4.2) should consider patching, as earlier versions are affected by security vulnerabilities.

IMPORTANT: InfoSol does not recommend BI 4.3 SP5 Patch 4 or BI 2025 SP0 Patch 8, as these patch levels were affected by a CMS clustering issue described in SAP Note 3724948.

InfoBurst

InfoSol also recommends that its InfoBurst customers use this opportunity to upgrade to InfoBurst 2026.2. InfoBurst software can be downloaded from the InfoSol Help Portal.

Previous SAP Security articles from Speak BO

How InfoSol Can Help

Don’t wait for security gaps to become business problems. With July’s SAP Security Patch Day and a successful IBIS conference behind us, now is the time to take a smarter, more proactive approach to your BusinessObjects landscape. InfoSol can help you evaluate risk, simplify patching, and align your environment with SAP’s roadmap—from BI 4.x stabilization to BI 2025 and UNX adoption to BI 2027 planning. Let’s make every update a step toward a stronger, more future-ready platform.

Contact InfoSol today to schedule a free patching assessment or upgrade consultation—and ensure your BI environment stays protected, optimized, and compliant.

About Dallas Marks

Dallas is a BI Technical Consultant at InfoSol, where he delivers consulting and training services focused on SAP BusinessObjects and information delivery. He is also a product specialist for InfoBurst and Squirrel365, helping organizations automate and scale their reporting processes. Dallas is a frequent contributor to the Speak BO community, sharing practical insights and real-world solutions.

Check Also

IBIS 2026 Dove Mountain Resort Night View

IBIS 2027 Save the Date: June 14-16

If you want to explore everything that’s happening with BusinessObjects and learn from top global …

Leave a Reply

Your email address will not be published. Required fields are marked *