Security Advisories  

We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.

The user interface, is designed to be as intuitive as possible but we'd love to hear your feedback and opinions.
We hope you like it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 791 and the highest CVSS score is 10.0.

 

 Severity
SAP© Security advisories 791
 System Types
Affected SAP© system types

 

Related note
3427178
CVSS
4.3

Affected system type
ABAP
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-30216] Missing Authorization check in SAP S/4 HANA (Cash Management)

 

Related note
3434839
CVSS
8.8

Affected system type
Java
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-27899] Security misconfiguration vulnerability in SAP NetWeaver AS Java User Management Engine

 

Related note
3430173
CVSS
4.3

Affected system type
ABAP
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-30217] Missing Authorization check in SAP S/4 HANA (Cash Management)

 

Related note
3438234
CVSS
7.2

Affected system type
ABAP
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-27901] Directory Traversal vulnerability in SAP Asset Accounting

 

Related note
3421453
CVSS
4.8

Affected system type
SAP Business Connector
Patchday
2024-04
Released on
2024/04/09

Description
[Multiple CVEs] Cross-Site Scripting (XSS) vulnerabilities in SAP Business Connector

 

Related note
3421384
CVSS
7.7

Affected system type
BI/BO platform
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-25646] Information Disclosure vulnerability in SAP BusinessObjects Web Intelligence

 

Related note
3359778
CVSS
6.5

Affected system type
Kernel
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-30218] Denial of service (DOS) vulnerability in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3442741
CVSS
6.8

Affected system type
SAP Edge Integration
Patchday
2024-04
Released on
2024/04/09

Description
Stack overflow vulnerability on the component images of SAP Integration Suite (EDGE INTEGRATION CELL)

 

Related note
3442378
CVSS
6.5

Affected system type
ABAP
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-28167] Missing Authorization check in SAP Group Reporting Data Collection (Enter Package Data)

 

Related note
3425188
CVSS
5.3

Affected system type
Java
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-27898] Server-Side Request Forgery in SAP NetWeaver (tc~esi~esp~grmg~wshealthcheck~ear)

 

Related note
3377979
CVSS
5.4

Affected system type
Kernel
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-27902] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP, applications based on SAPGUI for HTML (WebGUI)

 

Related note
3417399
CVSS
4.6

Affected system type
ABAP
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-22133] Improper Access Control in SAP Fiori Front End Server

 

Related note
3428847
CVSS
5.3

Affected system type
Java
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-25645] Information Disclosure vulnerability in SAP NetWeaver (Enterprise Portal)

 

Related note
3434192
CVSS
5.3

Affected system type
Java
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-28163] Information Disclosure vulnerability in SAP NetWeaver Process Integration (Support Web Pages)

 

Related note
3433192
CVSS
9.1

Affected system type
Java
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-22127] Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)

 

Related note
3425274
CVSS
9.4

Affected system type
SAP Build Apps
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2019-10744] Code Injection vulnerability in applications built with SAP Build Apps

 

Related note
3410615
CVSS
7.5

Affected system type
HANA platform
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2023-44487 ] Denial of service (DOS) in SAP HANA XS Classic and HANA XS Advanced

 

Related note
3425682
CVSS
5.3

Affected system type
Java
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-25644] Information Disclosure vulnerability in SAP NetWeaver (WSRM)

 

Related note
3419022
CVSS
4.3

Affected system type
ABAP
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-27900]Missing Authorization check in SAP ABAP Platform

 

Related note
3414195
CVSS
7.2

Affected system type
BI/BO platform
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2023-50164] Path Traversal Vulnerability in SAP BusinessObjects Business Intelligence Platform (Central Management Console)

 

Related note
3421659
CVSS
7.4

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22132] Code Injection vulnerability in SAP IDES Systems

 

Related note
3237638
CVSS
4.3

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-25643] Missing authorization check in SAP Fiori app ("My Overtime Requests")

 

Related note
2637727
CVSS
6.3

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-24739] Missing authorization check in SAP Bank Account Management

 

Related note
3404025
CVSS
5.4

Affected system type
SAP Enable Now
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22129] Cross-Site Scripting (XSS) vulnerability in SAP Companion

 

Related note
3426111
CVSS
8.6

Affected system type
Java
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-24743] XXE vulnerability in SAP NetWeaver AS Java (Guided Procedures)

 

Related note
2897391
CVSS
4.3

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/01

Description
[CVE-2024-24741] Missing Authorization check in SAP Master Data Governance Material

 

Related note
3158455
CVSS
4.1

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-24742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)

 

Related note
3424610
CVSS
7.4

Affected system type
SAP Cloud Connector
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-25642] Improper Certificate Validation in SAP Cloud Connector

 

Related note
3396109
CVSS
4.7

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22128] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Business Client for HTML

 

Related note
3417627
CVSS
8.8

Affected system type
Java
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application)

 

Related note
3360827
CVSS
5.3

Affected system type
Kernel
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-24740] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (SAP Kernel)

 

Related note
3420923
CVSS
9.1

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22131] Code Injection vulnerability in SAP ABA (Application Basis)

 

Related note
3410875
CVSS
7.6

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22130] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)

 

Related note
3413475
CVSS
9.1

Affected system type
SAP Edge Integration
Patchday
2024-01
Released on
2024/01/09

Description
[Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell

 

Related note
3190894
CVSS
3.7

Affected system type
SAP Marketing
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21734] URL Redirection vulnerability in SAP Marketing (Contacts App)

 

Related note
3392626
CVSS
4.1

Affected system type
Kernel / Web Dispatcher
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-22124] Information Disclosure vulnerability in SAP NetWeaver Internet Communication Manager

 

Related note
3389917
CVSS
7.5

Affected system type
Kernel
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2023-44487] Denial of service (DOS) in SAP Web Dispatcher, SAP NetWeaver Application server ABAP, and ABAP Platform

 

Related note
3386378
CVSS
7.4

Affected system type
SAP GUI / Frontend
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-22125] Information Disclosure vulnerability in Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge)

 

Related note
3260667
CVSS
6.4

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21736] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)

 

Related note
3411869
CVSS
8.4

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21737] Code Injection vulnerability in SAP Application Interface Framework (File Adapter)

 

Related note
3387737
CVSS
4.1

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21738] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform

 

Related note
3407617
CVSS
7.3

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21735] Improper Authorization check in SAP LT Replication Server

 

Related note
3412456
CVSS
9.1

Affected system type
BTP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA

 

Related note
3369353
CVSS
6.8

Affected system type
BI/BO platform
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-42476] Cross Site Scripting vulnerability in SAP BusinessObjects Web Intelligence

 

Related note
3392547
CVSS
4.1

Affected system type
ABAP
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-49581] SQL Injection vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform

 

Related note
3406244
CVSS
7.1

Affected system type
Android SDK
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-6542] Missing Authorization Check in SAP EMARSYS SDK ANDROID

 

Related note
3383321
CVSS
6.1

Affected system type
Java
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-42479] Cross-Site Scripting (XSS) vulnerability in SAP Biller Direct

 

Related note
3394567
CVSS
8.1

Affected system type
SAP Commerce
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-42481] Improper Access Control vulnerability in SAP Commerce Cloud

 

Related note
3385711
CVSS
7.3

Affected system type
SAP GUI / Frontend
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-49580] Information disclosure vulnerability in SAP GUI for WIndows and SAP GUI for Java

 

Related note
3363690
CVSS
3.5

Affected system type
ABAP
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-49058] Directory Traversal vulnerability in SAP Master Data Governance

 

Related note
3159329
CVSS
5.3

Affected system type
ABAP
Patchday
2023-12
Released on
2023/12/12

Description
Denial of service (DoS) vulnerability in JSZip library bundled within SAPUI5

 

Related note
3362463
CVSS
3.5

Affected system type
SAP Cloud Connector
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-49578] Denial of service (DOS) in SAP Cloud Connector

 

Related note
3395306
CVSS
6.4

Affected system type
ABAP
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-49587] Command Injection vulnerability in SAP Solution Manager

 

Related note
3406786
CVSS
4.3

Affected system type
SAP UI5
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-49584] Client-Side Desynchronization vulnerability in SAP Fiori Launchpad

 

Related note
3399691
CVSS
9.1

Affected system type
ABAP
Patchday
2023-12
Released on
2023/12/12

Description
Update 1 to 3350297 - [CVE-2023-36922] OS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)

 

Related note
3217087
CVSS
6.1

Affected system type
ABAP
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-49577] Cross-Site Scripting (XSS) vulnerability in the SAP HCM (SMART PAYE solution)

 

Related note
3382353
CVSS
7.5

Affected system type
BI/BO platform
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-42478] Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform

 

Related note
3411067
CVSS
9.1

Affected system type
BTP
Patchday
2023-12
Released on
2023/12/12

Description
[Multiple CVEs] Escalation of Privileges in SAP Business Technology Platform (BTP) Security Services Integration Libraries

 

Related note
3366410
CVSS
5.3

Affected system type
Java
Patchday
2023-11
Released on
2023/11/14

Description
[CVE-2023-42480] Information Disclosure in NetWeaver AS Java Logon

 

Related note
3362849
CVSS
5.3

Affected system type
Kernel
Patchday
2023-11
Released on
2023/11/14

Description
[CVE-2023-41366] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform

 

Related note
3355658
CVSS
9.6

Affected system type
SAP Business One
Patchday
2023-11
Released on
2023/11/14

Description
[CVE-2023-31403] Improper Access Control vulnerability in SAP Business One product installation

 

Related note
3338380
CVSS
4.3

Affected system type
SAP Business One
Patchday
2023-10
Released on
2023/10/10

Description
[CVE-2023-41365] Information Disclosure vulnerability in SAP Business One (B1i)

 

Related note
3333426
CVSS
6.5

Affected system type
Java
Patchday
2023-10
Released on
2023/10/26

Description
[CVE-2023-42477] Server-Side Request Forgery in SAP NetWeaver AS Java (GRMG Heartbeat application)

 

Related note
3222121
CVSS
4.3

Affected system type
ABAP
Patchday
2023-10
Released on
2023/10/10

Description
[CVE-2023-42475] Information Disclosure Vulnerability in Statutory Reporting

 

Related note
3357154
CVSS
6.5

Affected system type
SAP PowerDesigner
Patchday
2023-10
Released on
2023/10/10

Description
[CVE-2023-40310] Missing XML Validation vulnerability in SAP PowerDesigner Client (BPMN2 import)

 

Related note
3371873
CVSS
5.3

Affected system type
Java
Patchday
2023-10
Released on
2023/10/10

Description
Update 1 to Security Note 3324732: [CVE-2023-31405] Log Injection vulnerability in SAP NetWeaver AS for Java (Log Viewer)

 

Related note
3372991
CVSS
6.8

Affected system type
BI/BO platform
Patchday
2023-10
Released on
2023/10/10

Description
[CVE-2023-42474] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Web Intelligence

 

Related note
3355675
CVSS
2.7

Affected system type
ABAP
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-41368] Insecure Direct Object Reference (IDOR) vulnerability in SAP S/4HANA (Manage checkbook apps)

 

Related note
3357163
CVSS
6.3

Affected system type
PowerDesigner
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40621] Code Injection vulnerability in SAP PowerDesigner Client

 

Related note
3320355
CVSS
9.9

Affected system type
SAP BI
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40622] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management)

 

Related note
3327896
CVSS
7.5

Affected system type
Kernel
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40308] Memory Corruption vulnerability in SAP CommonCryptoLib

 

Related note
3340576
CVSS
9.8

Affected system type
Kernel, HANA...
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40309] Missing Authorization check in SAP CommonCryptoLib

 

Related note
3369680
CVSS
3.5

Affected system type
ABAP
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-41369] External Entity Loop vulnerability in SAP S/4HANA (Create Single Payment application)

 

Related note
3352453
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-37489] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Version Management System)

 

Related note
3348142
CVSS
5.3

Affected system type
Java
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-41367] Missing Authentication check in SAP NetWeaver (Guided Procedures)

 

Related note
3317702
CVSS
6.2

Affected system type
BI/BO platform
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40623] Arbitrary File Delete via Directory Junction in SAP BusinessObjects Suite(installer)

 

Related note
3370490
CVSS
8.7

Affected system type
BI/BO platform
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-42472] Insufficient File type validation in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)

 

Related note
3349805
CVSS
5.7

Affected system type
Java
Patchday
2023-09
Released on
2023/09/12

Description
Denial of service (DOS) vulnerability due to the usage of vulnerable version of Commons File Upload in SAP Quotation Management Insurance (FS-QUO)

 

Related note
3323163
CVSS
5.5

Affected system type
ABAP
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40624] Code Injection vulnerability in SAP NetWeaver AS ABAP (applications based on Unified Rendering)

 

Related note
3326361
CVSS
5.4

Affected system type
ABAP
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40625] Missing Authorization check in Manage Purchase Contracts App

 

Related note
3341934
CVSS
5.9

Affected system type
SAP Commerce Cloud
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37486] Information Disclosure vulnerability in SAP Commerce (OCC API)

 

Related note
3350494
CVSS
6.1

Affected system type
Java
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37488] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Process Integration

 

Related note
3346500
CVSS
8.8

Affected system type
SAP Commerce Cloud
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-39439] Improper authentication in SAP Commerce Cloud

 

Related note
3312586
CVSS
4.4

Affected system type
BI/BO platform
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-39440] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform

 

Related note
3312047
CVSS
7.5

Affected system type
BI/BO platform
Patchday
2023-08
Released on
2023/08/08

Description
Denial of Service (DoS) vulnerability due to the usage of vulnerable version of Commons FileUpload in SAP BusinessObjects Business Intelligence Platform (CMC)

 

Related note
3358328
CVSS
3.7

Affected system type
SAP Host Agent
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-36926] Information disclosure vulnerability in SAP Host Agent

 

Related note
3333616
CVSS
5.3

Affected system type
SAP Business One
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37487] Security Misconfiguration vulnerability in SAP Business One (Service Layer)

 

Related note
3149794
CVSS
6.1

Affected system type
SAP UI5
Patchday
2023-08
Released on
2023/08/08

Description
Cross-Site Scripting (XSS) vulnerabilities in jQuery-UI library bundled with SAPUI5

 

Related note
3156972
CVSS
6.1

Affected system type
ABAP
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-40306] URL Redirection vulnerability in SAP S/4HANA (Manage Catalog Items and Cross-Catalog search)

 

Related note
3317710
CVSS
7.6

Affected system type
BI/BO platform
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37490] Binary hijack in SAP BusinessObjects Business Intelligence Suite (installer)

 

Related note
2032723
CVSS
6.3

Affected system type
ABAP
Patchday
2023-08
Released on
2014/11/11

Description
Switchable authorization checks for RFC in SRM

 

Related note
3348000
CVSS
4.9

Affected system type
ABAP
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37492] Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3341599
CVSS
7.8

Affected system type
SAP PowerDesigner
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-36923] Code Injection vulnerability in SAP PowerDesigner

 

Related note
3337797
CVSS
7.1

Affected system type
SAP Business One
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-33993] SQL Injection vulnerability in SAP Business One (B1i Layer)

 

Related note
3358300
CVSS
7.6

Affected system type
SAP Business One
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-39437] Cross-Site Scripting (XSS) vulnerability in SAP Business One

 

Related note
3341460
CVSS
9.8

Affected system type
SAP PowerDesigner
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37483] Multiple Vulnerabilities in SAP PowerDesigner

 

Related note
3350297
CVSS
9.1

Affected system type
ABAP
Patchday
2023-08
Released on
2023/07/11

Description
[CVE-2023-36922] OS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)

 

Related note
3344295
CVSS
7.5

Affected system type
Kernel
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37491] Improper Authorization check vulnerability in SAP Message Server

 

Related note
2067220
CVSS
5.8

Affected system type
ABAP
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-39436] Information Disclosure in SAP Supplier Relationship Management

 

Related note
3233899
CVSS
8.6

Affected system type
Kernel
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-33987] Request smuggling and request concatenation vulnerability in SAP Web Dispatcher

 

Related note
3343564
CVSS
6.5

Affected system type
Java
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-35872] Missing Authentication check in SAP NetWeaver Process Integration (Message Display Tool)

 

Related note
3351410
CVSS
4.9

Affected system type
ABAP
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-36924] Log Injection vulnerability in SAP ERP Defense Forces and Public Security

 

Related note
3320702
CVSS
5.9

Affected system type
BI/BO platform
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-36917] Password Change rate limit bypass in SAP BusinessObjects Business Intelligence Platform

 

Related note
3348145
CVSS
7.2

Affected system type
Java
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-36921] Header Injection in SAP Solution Manager (Diagnostic Agent)

 

Related note
3318850
CVSS
6.0

Affected system type
Kernel
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-35874] Improper authentication vulnerability in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3352058
CVSS
7.2

Affected system type
Java
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-36925] Unauthenticated blind SSRF in SAP Solution Manager (Diagnostics agent)

 

Related note
3326769
CVSS
6.1

Affected system type
SAP Enable Now
Patchday
2023-07
Released on
2023/07/11

Description
[Multiple CVEs] Multiple Vulnerabilities in SAP Enable Now

 

Related note
3341211
CVSS
6.3

Affected system type
ABAP
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-35870] Improper Access Control in SAP S/4HANA (Manage Journal Entry Template)

 

Related note
3340735
CVSS
7.7

Affected system type
Kernel
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-35871] Memory Corruption vulnerability in SAP Web Dispatcher

 

Related note
3324732
CVSS
5.3

Affected system type
Java
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-31405] Log Injection vulnerability in SAP NetWeaver AS for Java (Log Viewer)

 

Related note
3088078
CVSS
4.5

Affected system type
BI/BO platform
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-33992] Missing Authorization Check in SAP Business Warehouse and SAP BW/4HANA

 

Related note
3331376
CVSS
8.7

Affected system type
ABAP
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-33989] Directory Traversal vulnerability in SAP NetWeaver (BI CONT ADD ON)

 

Related note
3343547
CVSS
6.5

Affected system type
Java
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-35873] Missing Authentication check in SAP NetWeaver Process Integration (Runtime Workbench)

 

Related note
3331029
CVSS
7.8

Affected system type
Sybase platform
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-33990] Denial of service (DOS) vulnerability in SAP SQL Anywhere

 

Related note
3331627
CVSS
6.1

Affected system type
Java
Patchday
2023-06
Released on
2023/06/13

Description
[CVE-2023-33985] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (Enterprise Portal)

 

Related note
3325642
CVSS
2.7

Affected system type
ABAP
Patchday
2023-06
Released on
2023/06/13

Description
[CVE-2023-32114] Denial of Service in SAP NetWeaver (Change and Transport System)

 

Related note
3318657
CVSS
6.4

Affected system type
SAP...
Patchday
2023-06
Released on
2023/06/13

Description
[CVE-2023-33984] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (Design Time Repository)

 

Related note
3324285
CVSS
8.2

Affected system type
SAP UI5
Patchday
2023-06
Released on
2023/06/13

Description
[CVE-2023-33991] Stored Cross-Site Scripting vulnerability in SAP UI5 (Variant Management)

 

Related note
2826092
CVSS
6.1

Affected system type
ABAP
Patchday
2023-06
Released on
2023/06/13

Description
[CVE-2023-33986] Cross-Site Scripting (XSS) vulnerability in SAP CRM ABAP (Grantor Management)

 

Related note
3322800
CVSS
6.1

Affected system type
ABAP
Patchday
2023-06
Released on
2023/06/13

Description
Update 1 to security note 3315971 - [CVE-2023-30742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)

 

Related note
3319400
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-31406] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform

 

Related note
3038911
CVSS
5.0

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-31404] Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Service)

 

Related note
3313484
CVSS
6.3

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30740] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform

 

Related note
3315979
CVSS
5.4

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-29188] Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI

 

Related note
3323415
CVSS
8.2

Affected system type
SAP Integrated...
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-29080] Privilege escalation vulnerability in SAP IBP, add-in for Microsoft Excel

 

Related note
3307833
CVSS
9.1

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-28762] Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Console)

 

Related note
2335198
CVSS
2.8

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-32112] Missing Authorization Check in Vendor Master Hierarchy

 

Related note
3320467
CVSS
7.5

Affected system type
SAP GUI / Frontend
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-32113] Information Disclosure vulnerability in SAP GUI for Windows

 

Related note
3315971
CVSS
6.1

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)

 

Related note
3300624
CVSS
7.5

Affected system type
SAP PowerDesigner
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-32111] Memory Corruption vulnerability in SAP PowerDesigner (Proxy)

 

Related note
3309935
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30741] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform

 

Related note
3302595
CVSS
3.7

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-28764] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform

 

Related note
3321309
CVSS
7.5

Affected system type
SAP Commerce
Patchday
2023-05
Released on
2023/05/09

Description
Information Disclosure vulnerability in SAP Commerce (Backoffice)

 

Related note
1794761
CVSS
4.2

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/23

Description
[CVE-2023-32115] SQL Injection in Master Data Synchronization (MDS COMPARE TOOL)

 

Related note
3317453
CVSS
8.2

Affected system type
Java
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30744] Improper access control during application start-up in SAP AS NetWeaver JAVA

 

Related note
3328495
CVSS
9.8

Affected system type
Reprise License Manager
Patchday
2023-05
Released on
2023/05/09

Description
Multiple vulnerabilities associated with Reprise License Manager 14.2 component used with SAP 3D Visual Enterprise License Manager

 

Related note
3312892
CVSS
5.4

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-31407] Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation

 

Related note
3301942
CVSS
7.9

Affected system type
SAP Plant Connectivity
Patchday
2023-05
Released on
2023/05/23

Description
[CVE-2023-2827] Missing Authentication in SAP Plant Connectivity and Production Connector for SAP Digital Manufacturing

 

Related note
3326210
CVSS
7.1

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30743] Improper Neutralization of Input in SAPUI5

 

Related note
3320145
CVSS
7.5

Affected system type
SAP Commerce
Patchday
2023-05
Released on
2023/05/09

Description
Denial of service (DOS) in SAP Commerce

 

Related note
3289994
CVSS
6.5

Affected system type
Java
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-28761] Missing Authentication check in SAP NetWeaver Enterprise Portal

 

Related note
3115598
CVSS
4.4

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29109] Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard)

 

Related note
3269352
CVSS
5.4

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29189] HTTP Verb Tampering vulnerability in SAP CRM (WebClient UI)

 

Related note
3305907
CVSS
8.7

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29186] Directory Traversal vulnerability in SAP NetWeaver ( BI CONT ADD ON)

 

Related note
3315312
CVSS
5.0

Affected system type
Kernel
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29108] IP filter vulnerability in ABAP Platform and SAP Web Dispatcher

 

Related note
3305369
CVSS
10.0

Affected system type
Java
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-27497] Multiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge and EventLogServiceCollector)

 

Related note
3316509
CVSS
4.7

Affected system type
SAP Commerce
Patchday
2023-04
Released on
2023/04/11

Description
Remote Code Execution vulnerability in SAP Commerce

 

Related note
3298961
CVSS
9.8

Affected system type
BI/BO platform
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-28765] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management )

 

Related note
3117978
CVSS
3.1

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29111] Information Disclosure vulnerability in SAP Application Interface Framework (ODATA service)

 

Related note
3309056
CVSS
6.0

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-27897] Code Injection vulnerability in SAP CRM

 

Related note
3275458
CVSS
6.1

Affected system type
Kernel
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-27499] Cross-Site Scripting (XSS) vulnerability in SAP GUI for HTML

 

Related note
3312733
CVSS
6.8

Affected system type
Java
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-26458] Information Disclosure vulnerability in SAP Landscape Management

 

Related note
3303060
CVSS
5.3

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29185] Denial of Service (DOS) in SAP NetWeaver AS for ABAP (Business Server Pages)

 

Related note
3301457
CVSS
4.3

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-1903] Missing Authorization check in SAP HCM Fiori App My Forms (Fiori 2.0)

 

Related note
3311624
CVSS
6.7

Affected system type
SAP GUI / Frontend
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29187] DLL Hijacking vulnerability in SapSetup (Software Installation Program)

 

Related note
3287784
CVSS
5.3

Affected system type
Java
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-24527] Improper Access Control in SAP NetWeaver AS Java for Deploy Service

 

Related note
3296378
CVSS
6.5

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-28763] - Denial of Service in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3114489
CVSS
3.7

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29112] Code Injection vulnerability in SAP Application Interface Framework (Message Monitoring)

 

Related note
3113349
CVSS
3.7

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29110] Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard)

 

Related note
3245526
CVSS
9.9

Affected system type
BI/BO platform
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-25616] Code Injection vulnerability in SAP Business Objects Business Intelligence Platform (CMC)

 

Related note
3288394
CVSS
5.3

Affected system type
Java
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-24526] Improper Access Control in SAP NetWeaver AS Java (Classload Service)

<