SAP Security Patch Day – May 2026

SAP issues monthly Security Patch Day Bulletins on the second Tuesday of every month- which has been synchronized with the Security Patch Day of other major software vendors. This month’s bulletin was issued on May 12, 2026, and contains 15 new security notesOne (1) of these notes applies to the SAP BusinessObjects Platform and has a medium severity.

Cross Site Request Forgery (CSRF) in SAP BusinessObjects Business Intelligence Platform

[CVE-2026-0502] The Cross Site Request Forgery (CSRF) in SAP BusinessObjects Business Intelligence Platform is described in CVE-2026-0502. The vulnerability has a score of 5.4 and its remedy, available in BI 4.3 SP5 Patch 5 and higher or BI 2025 SP0 Patch 1 and higher is described in SAP KB 3667593.

Recommendation

InfoSol recommends patching to either BI 4.3 SP5 Patch 5 and higher or BI 2025 SP0 Patch 9 and higher for all SAP BI customers not already on BI 4.3 SP5 Patch 5 and higher. These patches were released in March 2026. As always, review SAP’s release notes and patch upgrade guide, which are available on the SAP Help Portal.

Whether you choose BI 4.3 or BI 2025 will largely be determined by whether your organization still uses “classic” UNV universes. These universes are no longer supported in BI 2025 and must be converted to UNX format prior to upgrading to BI 2025. Choosing BI 4.3 or BI 2025 also depends on the age of your hardware and operating system, as many organizations adopting BI 2025 will likely want to deploy it on the latest version of Windows Server.

IMPORTANT: Support packs prior to BI 4.3 SP5 are no longer under patch support. Customers on BI 4.3 SP4 and earlier (this includes SAP BusinessObjects BI 4.2) should consider patching.

IMPORTANT: While there were no BusinessObjects CVE in the March 2026 note, there were some in the February 2026 and April 2026 notes that have medium and high severity that should be included in a comprehensive business case for patching. As a side benefit, the patches for these newer versions of BI 4.3 or BI 2025 include Apache Tomcat version 9.0.111 (see SAP KB 2112338). 

IMPORTANT: InfoSol does not recommend BI 4.3 SP5 Patch 4 or BI 2025 SP0 Patch 8, as these patch levels were affected by a CMS clustering issue described in SAP Note 3724948.

InfoBurst

InfoSol also recommends that its InfoBurst customers use this opportunity to upgrade to version 2026.1.1. InfoBurst software can be downloaded from the InfoSol Help Portal.

How InfoSol Can Help

Don’t wait for vulnerabilities to become disruptions. With this month’s SAP Security Patch Day introducing several high‑priority updates, now is the perfect time to take a strategic approach to your BusinessObjects environment. InfoSol can help you move beyond reactive patching by assessing your current risk posture, streamlining your update process, and aligning your platform with SAP’s long‑term roadmap. From stabilizing existing BI 4.x deployments to guiding upgrades into BI 2025 and accelerating your shift to UNX universes, our team delivers practical, hands‑on expertise every step of the way. Let’s turn patching into an opportunity to strengthen performance, security, and future readiness.

Contact InfoSol today to schedule a free patching assessment or upgrade consultation—and ensure your BI environment stays protected, optimized, and compliant.

About Dallas Marks

Dallas is a BI Technical Consultant at InfoSol, where he delivers consulting and training services focused on SAP BusinessObjects and information delivery. He is also a product specialist for InfoBurst and Squirrel365, helping organizations automate and scale their reporting processes. Dallas is a frequent contributor to the Speak BO community, sharing practical insights and real-world solutions.

Check Also

IBIS 2026 Dove Mountain Resort Night View

IBIS 2027 Save the Date: June 14-16

If you want to explore everything that’s happening with BusinessObjects and learn from top global …

Leave a Reply

Your email address will not be published. Required fields are marked *