Security Advisories
We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.
We hope you like it!
This time we found critical correction advisiories. We count 667 and the highest CVSS score is 10.0.
Severity
SAP© Security advisories 667
System Types
Affected SAP© system types
Affected system
type
Reprise License Manager
Patchday
2023-05
Released
on
2023/05/09
Description
Multiple vulnerabilities associated with Reprise License Manager 14.2 component used with SAP 3D Visual Enterprise License Manager
Affected system
type
ABAP
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-29188] Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI
Affected system
type
ABAP
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-31407] Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation
Affected system
type
ABAP
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-30742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Affected system
type
BI/BO platform
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-30741] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform
Affected system
type
BI/BO platform
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-28764] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform
Affected system
type
BI/BO platform
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-30740] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform
Affected system
type
SAP PowerDesigner
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-32111] Memory Corruption vulnerability in SAP PowerDesigner (Proxy)
Affected system
type
SAP Integrated...
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-29080] Privilege escalation vulnerability in SAP IBP, add-in for Microsoft Excel
Affected system
type
SAP Commerce
Patchday
2023-05
Released
on
2023/05/09
Description
Information Disclosure vulnerability in SAP Commerce (Backoffice)
Affected system
type
BI/BO platform
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-31404] Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Service)
Affected system
type
SAP GUI / Frontend
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-32113] Information Disclosure vulnerability in SAP GUI for Windows
Affected system
type
BI/BO platform
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-28762] Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Console)
Affected system
type
BI/BO platform
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-31406] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform
Affected system
type
Java
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-30744] Improper access control during application start-up in SAP AS NetWeaver JAVA
Affected system
type
SAP Commerce
Patchday
2023-05
Released
on
2023/05/09
Description
Denial of service (DOS) in SAP Commerce
Affected system
type
ABAP
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-32112] Missing Authorization Check in Vendor Master Hierarchy
Affected system
type
ABAP
Patchday
2023-05
Released
on
2023/05/09
Description
[CVE-2023-30743] Improper Neutralization of Input in SAPUI5
Affected system
type
ABAP
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-1903] Missing Authorization check in SAP HCM Fiori App My Forms (Fiori 2.0)
Affected system
type
Java
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-27497] Multiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge and EventLogServiceCollector)
Affected system
type
ABAP
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-29111] Information Disclosure vulnerability in SAP Application Interface Framework (ODATA service)
Affected system
type
Java
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-24527] Improper Access Control in SAP NetWeaver AS Java for Deploy Service
Affected system
type
ABAP
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-29185] Denial of Service (DOS) in SAP NetWeaver AS for ABAP (Business Server Pages)
Affected system
type
ABAP
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-29189] HTTP Verb Tampering vulnerability in SAP CRM (WebClient UI)
Affected system
type
ABAP
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-27897] Code Injection vulnerability in SAP CRM
Affected system
type
BI/BO platform
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-28765] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management )
Affected system
type
Kernel
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-27499] Cross-Site Scripting (XSS) vulnerability in SAP GUI for HTML
Affected system
type
Kernel
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-29108] IP filter vulnerability in ABAP Platform and SAP Web Dispatcher
Affected system
type
ABAP
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-29112] Code Injection vulnerability in SAP Application Interface Framework (Message Monitoring)
Affected system
type
Java
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-26458] Information Disclosure vulnerability in SAP Landscape Management
Affected system
type
SAP Commerce
Patchday
2023-04
Released
on
2023/04/11
Description
Remote Code Execution vulnerability in SAP Commerce
Affected system
type
ABAP
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-29186] Directory Traversal vulnerability in SAP NetWeaver ( BI CONT ADD ON)
Affected system
type
ABAP
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-29109] Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard)
Affected system
type
ABAP
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-29110] Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard)
Affected system
type
SAP GUI / Frontend
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-29187] DLL Hijacking vulnerability in SapSetup (Software Installation Program)
Affected system
type
Java
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-28761] Missing Authentication check in SAP NetWeaver Enterprise Portal
Affected system
type
ABAP
Patchday
2023-04
Released
on
2023/04/11
Description
[CVE-2023-28763] - Denial of Service in SAP NetWeaver AS for ABAP and ABAP Platform
Affected system
type
BI/BO platform
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-25616] Code Injection vulnerability in SAP Business Objects Business Intelligence Platform (CMC)
Affected system
type
ABAP
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-25615] SQL Injection vulnerability in SAP ABAP Platform
Affected system
type
ABAP
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-27893] Arbitrary Code Execution in SAP Solution Manager and ABAP managed systems (ST-PI)
Affected system
type
Java
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-24526] Improper Access Control in SAP NetWeaver AS Java (Classload Service)
Affected system
type
ABAP
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-0021] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver
Affected system
type
BI/BO platform
Patchday
2023-03
Released
on
2023/03/14
Description
[Multiple CVEs] Multiple vulnerabilities in the SAP BusinessObjects Business Intelligence platform
Affected system
type
ABAP
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-26459] Multiple vulnerabilities in SAP NetWeaver AS for ABAP and ABAP Platform
Affected system
type
Java
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-23857] Improper Access Control in SAP NetWeaver AS for Java
Affected system
type
ABAP
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-27500] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-27269] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Affected system
type
Java
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-26460] Improper Access Control in SAP NetWeaver AS Java (Cache Management Service)
Affected system
type
Java
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-27268] Improper Access Control in SAP NetWeaver AS Java (Object Analyzing Service)
Affected system
type
ABAP
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-26457] Cross-Site Scripting (XSS) vulnerability in SAP Content Server
Affected system
type
ABAP
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-27270] Denial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP Platform
Affected system
type
Java
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-26461] XML External Entity (XXE) vulnerability in SAP NetWeaver (SAP Enterprise Portal)
Affected system
type
SAP Host Agent
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-27498] Memory Corruption vulnerability in SAPOSCOL
Affected system
type
SAP Authenticator for Android
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-27895] Information Disclosure vulnerability in SAP Authenticator for Android
Affected system
type
BI/BO platform
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-25617] OS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform (Adaptive Job Server)
Affected system
type
ABAP
Patchday
2023-03
Released
on
2023/03/14
Description
[CVE-2023-27501] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-24524] Missing Authorization check in SAP S/4 HANA Map Treasury Correspondence Format Data
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-23855] URL Redirection vulnerability in SAP Solution Manager
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-24528] Missing Authorization Check in SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests)
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-23854] Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-0024] Cross Site Scripting in SAP Solution Manager (BSP Application)
Affected system
type
BI/BO platform
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-24530] Unrestricted Upload of File in SAP BusinessObjects Business Intelligence Platform (CMC)
Affected system
type
SAP Host Agent
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-24523] Privilege Escalation vulnerability in SAP Host Agent (Start Service)
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-23853] URL Redirection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-23858] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-24522] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Framework)
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-24521] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Framework)
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-0025] Cross Site Scripting in SAP Solution Manager (BSP Application)
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-24529] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (Business Server Pages application)
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[Multiple CVEs] Multiple vulnerabilities in SAP NetWeaver AS for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-0019] Missing Authorization check in SAP GRC (Process Control)
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-23852] Cross-Site Scripting (XSS) vulnerability in SAP Solution Manager 7.2
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-23851] Unrestricted File Upload in SAP Business Planning and Consolidation
Affected system
type
BI/BO platform
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-0020] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence platform
Affected system
type
BI/BO platform
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-23856] Cross-Site Scripting (XSS) vulnerability in Web Intelligence Interface
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-25614] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Framework)
Affected system
type
ABAP
Patchday
2023-02
Released
on
2023/02/14
Description
[CVE-2023-24525] Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI
Affected system
type
SAP Host Agent
Patchday
2023-01
Released
on
2023/01/10
Description
[CVE-2023-0012] Local Privilege Escalation in SAP Host Agent (Windows)
Affected system
type
Kernel / ABAP
Patchday
2023-01
Released
on
2023/01/10
Description
[CVE-2023-0014] Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2023-01
Released
on
2023/01/10
Description
[CVE-2023-0023] Information Disclosure in SAP Bank Account Management (Manage Banks)
Affected system
type
BI/BO platform
Patchday
2023-01
Released
on
2023/01/10
Description
[CVE-2023-0018] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)
Affected system
type
BI/BO platform
Patchday
2023-01
Released
on
2023/01/10
Description
[CVE-2023-0022] Code Injection vulnerability in SAP BusinessObjects Business Intelligence platform (Analysis edition for OLAP)
Affected system
type
SAP Business Planning...
Patchday
2023-01
Released
on
2023/01/10
Description
[CVE-2023-0016] SQL Injection vulnerability in SAP Business Planning and Consolidation MS
Affected system
type
ABAP
Patchday
2023-01
Released
on
2023/01/10
Description
[CVE-2023-0013] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Affected system
type
BI/BO platform
Patchday
2023-01
Released
on
2023/01/10
Description
[CVE-2023-0015] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence (Web Intelligence)
Affected system
type
Java
Patchday
2023-01
Released
on
2023/01/10
Description
[CVE-2023-0017] Improper access control in SAP NetWeaver AS for Java
Affected system
type
ABAP
Patchday
2022-12
Released
on
2022/12/13
Description
[CVE-2022-41275] Offener Redirect in SAP Solutions Manager (Enterprise Search)
Affected system
type
SAP Commerce
Patchday
2022-12
Released
on
2022/12/13
Description
[CVE-2022-41266] Cross-Site Scripting (XSS) vulnerability in SAP Commerce
Affected system
type
ABAP
Patchday
2022-12
Released
on
2022/12/13
Description
[CVE-2022-41264] Code Injection vulnerability in SAP BASIS
Affected system
type
Java
Patchday
2022-12
Released
on
2022/12/13
Description
[CVE-2022-41262] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for Java (Http Provider Service)
Affected system
type
ABAP
Patchday
2022-12
Released
on
2022/12/13
Description
Update 1 to Security Note 2872782 - [CVE-2020-6215] URL Redirection vulnerability in SAP NetWeaver AS ABAP (BSP Test Application)
Affected system
type
Java
Patchday
2022-12
Released
on
2022/12/13
Description
[CVE-2022-41272] Improper access control in SAP NetWeaver AS Java (User Defined Search)
Affected system
type
ABAP
Patchday
2022-12
Released
on
2022/12/13
Description
[CVE-2022-41268] Privilege escalation vulnerability in SAP Business Planning and Consolidation
Affected system
type
BI/BO platform
Patchday
2022-12
Released
on
2022/12/13
Description
[CVE-2022-41267] Server-Side Request Forgery vulnerability in SAP BusinessObjects Business Intelligence Platform
Affected system
type
Java
Patchday
2022-12
Released
on
2022/12/13
Description
[CVE-2022-41271] Improper access control in SAP NetWeaver AS Java (Messaging System)
Affected system
type
SAP Commerce
Patchday
2022-12
Released
on
2022/12/13
Description
Remote Code Execution vulnerability associated with Apache Commons Text in SAP Commerce
Affected system
type
Java
Patchday
2022-12
Released
on
2022/12/13
Description
[CVE-2022-41261] Improper Access Control in SAP Solution Manager (Diagnostic Agent)
Affected system
type
Java
Patchday
2022-12
Released
on
2022/12/13
Description
[CVE-2022-41273] URL Redirection vulnerability in SAP Sourcing and SAP Contract Lifecycle Management
Affected system
type
SAP Disclosure Management
Patchday
2022-12
Released
on
2022/12/13
Description
[CVE-2022-41274] Missing Authorization Checks in SAP Disclosure Management
Affected system
type
BI/BO platform
Patchday
2022-12
Released
on
2022/12/13
Description
[CVE-2022-41263] Missing authentication check vulnerability in SAP Business Objects Business Intelligence Platform (Web intelligence)
Affected system
type
Java
Patchday
2022-11
Released
on
2022/11/08
Description
[CVE-2022-41207] URL Redirection vulnerability in SAP Biller Direct
Affected system
type
ABAP
Patchday
2022-11
Released
on
2022/11/08
Description
[CVE-2022-41214] Multiple vulnerabilities in SAP NetWeaver Application Server ABAP and ABAP Platform
Affected system
type
SAP UI5 SAP Fiori
Patchday
2022-11
Released
on
2022/11/08
Description
Insufficient Session Expiration in Central Fiori Launchpad
Affected system
type
ABAP
Patchday
2022-11
Released
on
2022/11/08
Description
[CVE-2022-41215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform
Affected system
type
ABAP, Java
Patchday
2022-11
Released
on
2022/11/08
Description
[CVE-2021-20223] Multiple Vulnerabilities in SQlite bundled with SAPUI5
Affected system
type
Sybase platform
Patchday
2022-11
Released
on
2022/11/08
Description
[CVE-2022-41259] Denial of service (DOS) in SAP SQL Anywhere
Affected system
type
SAP GUI
Patchday
2022-11
Released
on
2022/11/08
Description
[CVE-2022-41205] Code injection vulnerability in SAP GUI for Windows
Affected system
type
SAP Financial Consolidation
Patchday
2022-11
Released
on
2022/11/08
Description
[CVE-2022-41258] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation
Affected system
type
BI/BO platform
Exploit available
Patchday
2022-11
Released
on
2022/11/08
Description
[CVE-2022-41203] Insecure Deserialization of Untrusted Data in SAP BusinessObjects Business Intelligence Platform (Central Management Console and BI Launchpad)
Affected system
type
SAP 3D Visual Enterprise
Patchday
2022-11
Released
on
2022/11/08
Description
[CVE-2022-41211] Arbitrary Code Execution vulnerability in SAP 3D Visual Enterprise Author and SAP 3D Visual Enterprise Viewer
Affected system
type
BI/BO platform
Patchday
2022-10
Released
on
2022/10/11
Description
[CVE-2022-39013] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Program Objects)
Affected system
type
BI/BO platform
Patchday
2022-10
Released
on
2022/10/11
Description
[CVE-2022-41206] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform / Analysis for OLAP
Affected system
type
BI/BO platform
Patchday
2022-10
Released
on
2022/10/11
Description
[CVE-2022-39015] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform(AdminTools/ Query Builder)
Affected system
type
SAP 3D Visual Enterprise
Patchday
2022-10
Released
on
2022/10/11
Description
[Multiple CVEs] Multiple vulnerabilities in SAP 3D Visual Enterprise Author
Affected system
type
SAP Customer Data Cloud
Patchday
2022-10
Released
on
2022/10/11
Description
[CVE-2022-41209] Information Disclosure Vulnerability in SAP Customer Data Cloud (Gigya)
Affected system
type
BI/BO platform
Patchday
2022-10
Released
on
2022/10/11
Description
[CVE-2022-35296] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Version Management System)
Affected system
type
SAP Commerce
Patchday
2022-10
Released
on
2022/10/11
Description
Cross-Site Scripting (XSS) vulnerability in SAP Commerce
Affected system
type
ABAP
Patchday
2022-10
Released
on
2022/10/11
Description
Information Disclosure vulnerability in Master Data Governance
Affected system
type
SAP Enable Now
Patchday
2022-10
Released
on
2022/10/11
Description
[CVE-2022-35297] Stored Cross-Site Scripting (XSS) vulnerability in SAP Enable Now
Affected system
type
SAP Customer Data Cloud
Patchday
2022-10
Released
on
2022/10/11
Description
[CVE-2022-41210] Information Disclosure Vulnerability in SAP Customer Data Cloud (Gigya)
Affected system
type
BI/BO platform
Patchday
2022-10
Released
on
2022/10/11
Description
[CVE-2022-35226] Cross-Site Scripting (XSS) vulnerability in Data Services Management Console
Affected system
type
SAP 3D Visual Enterprise
Patchday
2022-10
Released
on
2022/10/11
Description
[Multiple CVEs] Multiple vulnerabilities in SAP 3D Visual Enterprise Viewer
Affected system
type
Java
Patchday
2022-10
Released
on
2022/10/11
Description
[CVE-2022-39802] File path traversal vulnerability in SAP Manufacturing Execution
Affected system
type
ABAP
Patchday
2022-10
Released
on
2022/10/11
Description
Missing authorization check in SAP Automotive Solutions
Affected system
type
BI/BO platform
Patchday
2022-10
Released
on
2022/10/11
Description
[CVE-2022-39800] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI LaunchPad)
Affected system
type
Sybase platform
Patchday
2022-10
Released
on
2022/10/11
Description
[CVE-2022-35299] Buffer Overflow in SAP SQL Anywhere and SAP IQ
Affected system
type
SAP Host Agent
Patchday
2022-09
Released
on
2022/09/13
Description
[CVE-2022-35295] Privilege Escalation Vulnerability in SAPOSCOL on Unix
Affected system
type
Java
Patchday
2022-09
Released
on
2022/09/13
Description
[CVE-2022-35298] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC)
Affected system
type
ABAP
Patchday
2022-09
Released
on
2022/09/13
Description
[CVE-2022-35294] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
Affected system
type
ABAP
Patchday
2022-09
Released
on
2022/09/13
Description
[CVE-2022-39799] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad)
Affected system
type
SAP Business One
Patchday
2022-09
Released
on
2022/09/13
Description
[CVE-2022-35292] Windows Unquoted Service Path issue in SAP Business One
Affected system
type
BI/BO platform
Patchday
2022-09
Released
on
2022/09/13
Description
[CVE-2022-39014] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (CMC)
Affected system
type
ABAP
Patchday
2022-09
Released
on
2022/09/13
Description
Missing authorization check in Consumption of CDS Views (or) OData Services in QM-QN
Affected system
type
ABAP
Patchday
2022-09
Released
on
2022/09/13
Description
Update 1 to Security Note 3165333 - [CVE-2022-28215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform
Affected system
type
ABAP
Patchday
2022-09
Released
on
2022/09/13
Description
Information Disclosure vulnerability in SAP CRM WebClient
Affected system
type
ABAP
Patchday
2022-09
Released
on
2022/09/13
Description
[CVE-2022-39801] Insufficient Firefighter Session Expiration in SAP GRC Access Control Emergency Access Management
Affected system
type
SAP Authenticator for Android
Patchday
2022-08
Released
on
2022/08/09
Description
[CVE-2022-35290] Information Disclosure in SAP Authenticator for Android
Affected system
type
SAP Landscape...
Patchday
2022-08
Released
on
2022/07/26
Description
Information Disclosure in SAP Landscape Management
Affected system
type
BI/BO platform
Patchday
2022-08
Released
on
2022/08/09
Description
[CVE-2022-31596] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Monitoring DB)
Affected system
type
BI/BO platform
Patchday
2022-08
Released
on
2022/08/09
Description
[CVE-2022-32245] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Open Document)
Affected system
type
BI/BO platform
Patchday
2022-08
Released
on
2022/08/09
Description
[CVE-2022-32244] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Commentary DB)
Affected system
type
ABAP
Patchday
2022-08
Released
on
2022/08/09
Description
Missing Authorization check in Portugal Digital Signature
Affected system
type
SAP Enable Now
Patchday
2022-08
Released
on
2022/08/09
Description
[CVE-2022-35293] Missing authorization check in SAP Enable Now Manager
Affected system
type
SAP GUI / Frontend
Patchday
2022-08
Released
on
2022/08/09
Description
Information Disclosure vulnerability in SAP Business Client
Affected system
type
Java
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35170] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
Java
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35172] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
Java
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35225] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
ABAP
Patchday
2022-07
Released
on
2022/07/12
Description
Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Affected system
type
BI/BO platform
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35228] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)
Affected system
type
SAP Business One
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-28771] Missing Authentication check in SAP Business One (License service API)
Affected system
type
Java
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35224] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Portal
Affected system
type
SAP 3D Visual Enterprise
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35171] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
Java
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-32247] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
ABAP
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-31597] Missing Authorization check in SAP S/4HANA(business partner extension for Spain/Slovakia)
Affected system
type
BI/BO platform
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-31598] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects
Affected system
type
SAP Business One
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-32249] Information Disclosure vulnerability in SAP Business One
Affected system
type
SAP Business One
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-31593] Code Injection vulnerability in SAP Business One
Affected system
type
ABAP
Patchday
2022-07
Released
on
2022/07/12
Description
Information Disclosure vulnerability in ABAP Platform
Affected system
type
BI/BO platform
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-32246] SQL Injection vulnerability in SAP BusinessObjects Business Intelligence Platform (Visual Difference Application)
Affected system
type
BI/BO platform
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35169] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (LCM)
Affected system
type
BI/BO platform
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-31591] Privilege Escalation vulnerability in SAP BusinessObjects (BW Publisher Service)
Affected system
type
SAP Business One
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35168] Denial of Service vulnerability in SAP Business One