Security Advisories  

We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.

The user interface, is designed to be as intuitive as possible but we'd love to hear your feedback and opinions.
We hope you like it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 486 and the highest CVSS score is 10.0.

 

 Severity
SAP© Security advisories 486
 System Types
Affected SAP© system types

 

Related note
2756188
CVSS
6.3

Affected system type
UI5
Patchday
2022-05
Released on
2022/05/10

Description
Cross-Site Request Forgery (CSRF) vulnerability in F0673 Approve Bank Payments front-end

 

Related note
3146336
CVSS
5.4

Affected system type
ABAP
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-29610] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP

 

Related note
2754555
CVSS
6.3

Affected system type
ABAP
Patchday
2022-05
Released on
2022/05/10

Description
Cross-Site Request Forgery (CSRF) vulnerability in F0673 Approve Bank Payments back-end

 

Related note
2998510
CVSS
7.8

Affected system type
BI/BO platform
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-28214] Central Management Server Information Disclosure in Business Intelligence Update

 

Related note
3145702
CVSS
5.3

Affected system type
SAP Host AgentKernel
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-29616] Memory Corruption vulnerability in SAP Host Agent, SAP NetWeaver and ABAP Platform

 

Related note
3165801
CVSS
6.5

Affected system type
ABAP
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-29611] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
3143161
CVSS
4.3

Affected system type
ABAP
Patchday
2022-05
Released on
2022/05/10

Description
Missing Authorization check for UI5 flexibility key user functionality

 

Related note
3145046
CVSS
8.3

Affected system type
Kernel
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-27656] Cross-Site Scripting (XSS) vulnerability in administration UI of SAP Webdispatcher and SAP Netweaver AS for ABAP and Java (ICM)

 

Related note
3158188
CVSS
5.3

Affected system type
SAP Host Agent
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-28774] Information Disclosure vulnerability in SAP Host Agent logfile

 

Related note
3164677
CVSS
6.5

Affected system type
ABAP
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-29613] Information Disclosure vulnerability in SAP Employee Self Service(Fiori My Leave Request)

 

Related note
3189409
CVSS
9.8

Affected system type
SAP Business One Cloud
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in in SAP Business One Cloud

 

Related note
3158613
CVSS
9.1

Affected system type
Java
Patchday
2022-04
Released on
2022/04/12

Description
Update 1 to Security Note 3022622 - [CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence

 

Related note
3145769
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-27667] Information Disclosure vulnerability in CMC

 

Related note
3132633
CVSS
5.4

Affected system type
SAP GUI / Frontend
Patchday
2022-04
Released on
2022/04/12

Description
Information Disclosure vulnerability in SAP GUI for Windows

 

Related note
3165333
CVSS
4.7

Affected system type
ABAP
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-28215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform

 

Related note
3130497
CVSS
8.2

Affected system type
BI/BO platform
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-27671] CSRF token visible in one of the URL in SAP Business Intelligence Platform.

 

Related note
3148377
CVSS
6.5

Affected system type
Java
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-28217] Missing XML Validation vulnerability in SAP NW EP WPC

 

Related note
3055044
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-28213] Missing XML Validation vulnerability in SAP BusinessObjects Business Intelligence Platform (dswsbobje - SOAP Web services)

 

Related note
3137191
CVSS
6.8

Affected system type
BI/BO platform
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-22541] Information Disclosure vulnerability in SAP BusinessObjects Platform

 

Related note
3163583
CVSS
6.1

Affected system type
Java
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-26105] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3148094
CVSS
6.5

Affected system type
Sybase
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-27670] Denial of service (DOS) in SQL Anywhere

 

Related note
3189429
CVSS
9.8

Affected system type
Java
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in PowerDesigner Web (up to including 16.7 SP05 PL01)

 

Related note
3155609
CVSS
7.0

Affected system type
SAP Commerce
Patchday
2022-04
Released on
2022/04/12

Description
Privilege escalation vulnerability in Apache Tomcat server component of SAP Commerce

 

Related note
3189428
CVSS
9.8

Affected system type
SAP HANA Platform
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP HANA Extended Application Services

 

Related note
3165856
CVSS
4.3

Affected system type
SAP Innovation Management
Patchday
2022-04
Released on
2022/03/28

Description
[CVE-2022-27658] Missing authorization check in SAP Innovation Management

 

Related note
3150845
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-28216] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI Workspace)

 

Related note
3138299
CVSS
4.1

Affected system type
Adobe LiveCycle Designer
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2021-44832] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP NetWeaver ABAP Server and ABAP Platform (Adobe LiveCycle Designer 11.0)

 

Related note
3111293
CVSS
4.9

Affected system type
Kernel
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-28773] Denial of service (DOS) in SAP Web Dispatcher and SAP Netweaver (Internet Communication Manager)

 

Related note
3170990
CVSS
9.8

Affected system type
Any
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-22965] Central Security Note for Remote Code Execution vulnerability associated with Spring Framework

 

Related note
3187290
CVSS
9.8

Affected system type
SAP Customer Checkout
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Checkout

 

Related note
3126557
CVSS
6.1

Affected system type
ABAP
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-28770] Cross-Site Scripting (XSS) vulnerability in SAPUI5 (vbm library)

 

Related note
3101986
CVSS
4.1

Affected system type
ABAP
Patchday
2022-04
Released on
2022/04/12

Description
Enable CSP support for OP1909 in SAP CRM WebClient UI

 

Related note
3189635
CVSS
9.8

Affected system type
SAP Customer...
Patchday
2022-04
Released on
2022/04/14

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Profitability Analytics

 

Related note
3111311
CVSS
7.5

Affected system type
Kernel
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-28772]Denial of service (DOS) in SAP Web Dispatcher and SAP Netweaver (Internet Communication Manager)

 

Related note
3163703
CVSS
6.1

Affected system type
ABAP
Patchday
2022-04
Released on
2022/04/12

Description
Multiple Vulnerabilities in URI.js bundled with SAPUI5

 

Related note
3171258
CVSS
9.8

Affected system type
SAP Commerce
Patchday
2022-04
Released on
2022/04/18

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Commerce

 

Related note
3159091
CVSS
2.7

Affected system type
SAP Solution Manager...
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-27657] Directory Traversal vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)

 

Related note
3152442
CVSS
5.3

Affected system type
Java
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-27669] Missing Authentication check in XML Data Archiving Service

 

Related note
3143437
CVSS
6.5

Affected system type
SAP 3D Visual Enterprise
Patchday
2022-04
Released on
2022/04/12

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3147283
CVSS
5.4

Affected system type
SAP Solution Manager...
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-24399] Cross-Site Scripting (XSS) vulnerability in SAP Focused Run (Real User Monitoring)

 

Related note
3146261
CVSS
6.1

Affected system type
Java
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-24395] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3149805
CVSS
8.1

Affected system type
ABAP
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-26101] Cross-Site Scripting (XSS) vulnerability in SAP Fiori launchpad

 

Related note
3144941
CVSS
5.4

Affected system type
SAP Financial Consolidation
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-26104] Missing Authorization check in SAP Financial Consolidation

 

Related note
3145987
CVSS
9.3

Affected system type
SAP Solution Manager...
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-24396] Missing Authentication check in SAP Focused Run (Simple Diagnostics Agent 1.0)

 

Related note
3154684
CVSS
10.0

Affected system type
SAP Work Manager
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Work Manager

 

Related note
3145997
CVSS
5.4

Affected system type
ABAP
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-26102] Missing authorization check in SAP NetWeaver Application Server for ABAP

 

Related note
3132360
CVSS
3.7

Affected system type
Java
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-26103] Information Disclosure vulnerability in SAP NetWeaver(Real Time Messaging Framework)

 

Related note
3103424
CVSS
5.0

Affected system type
BI/BO platform
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-24398] Information Disclosure vulnerability in SAP Business Objects Business Intelligence Platform

 

Related note
3147102
CVSS
5.3

Affected system type
SAP Solution Manager...
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-22547] Information Disclosure vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)

 

Related note
3146260
CVSS
6.1

Affected system type
Java
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-24397] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3104349
CVSS
3.3

Affected system type
ABAP
Patchday
2022-03
Released on
2022/03/22

Description
Missing authorization check in S/4HANA finance for advanced payment management

 

Related note
1753378
CVSS
5.3

Affected system type
Java
Patchday
2022-03
Released on
2013/08/13

Description
Directory traversal in Web Container

 

Related note
3111110
CVSS
4.8

Affected system type
SAPCAR
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-26100] Denial of service (DOS) in SAPCAR

 

Related note
3116223
CVSS
3.7

Affected system type
Kernel
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22543] Denial of service (DOS) in SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel)

 

Related note
3139893
CVSS
10.0

Affected system type
None
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Dynamic Authorization Management

 

Related note
3123396
CVSS
10.0

Affected system type
Kernel
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22536] Request smuggling and request concatenation in SAP NetWeaver, SAP Content Server and SAP Web Dispatcher

 

Related note
3128473
CVSS
4.9

Affected system type
ABAP
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22545] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform

 

Related note
3140587
CVSS
7.1

Affected system type
ABAP
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22540] SQL Injection vulnerability in SAP NetWeaver AS ABAP (Workplace Server)

 

Related note
3142773
CVSS
10.0

Affected system type
SAP Commerce
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Commerce

 

Related note
3126489
CVSS
6.5

Affected system type
ABAP
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22535] Missing Authorization check in SAP ERP HCM

 

Related note
3124994
CVSS
4.7

Affected system type
ABAP
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22534] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver

 

Related note
2531036
CVSS
6.3

Affected system type
ABAP
Patchday
2022-02
Released on
2019/04/09

Description
Switchable Authorization checks for RFC BCA_DIM_RESET_TRIGGER_TABLE in Loans (FI-CAX-FS)

 

Related note
3130920
CVSS
10.0

Affected system type
SAP Data Intelligence
Patchday
2022-02
Released on
2022/01/18

Description
Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Data Intelligence 3 (on-premise)

 

Related note
3134684
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2022-02
Released on
2022/02/08

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3107196
CVSS
4.3

Affected system type
ABAP
Patchday
2022-02
Released on
2022/01/25

Description
Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver AS ABAP within Web Dynpro ABAP

 

Related note
3140564
CVSS
5.6

Affected system type
SAP Adaptive Server...
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22528] Information Disclosure in SAP Adaptive Server Enterprise

 

Related note
3126748
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22546] XSS vulnerability in SAP Business Objects Web Intelligence (BI Launchpad)

 

Related note
3123427
CVSS
8.1

Affected system type
Kernel
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22532] HTTP Request Smuggling in SAP NetWeaver Application Server Java

 

Related note
3140940
CVSS
9.1

Affected system type
Java
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22544] Missing segregation of duties in SAP Solution Manager Diagnostics Root Cause Analysis Tools

 

Related note
3142092
CVSS
6.5

Affected system type
ABAP
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22542] Information Disclosure vulnerability in SAP S/4HANA (Supplier Factsheet and Enterprise Search for Business Partner, Supplier and Customer)

 

Related note
3106528
CVSS
6.5

Affected system type
SAP Business One
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44234] Information Disclosure vulnerability in SAP Business One

 

Related note
3136094
CVSS
10.0

Affected system type
SAP Digital...
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Digital Manufacturing Cloud for Edge Computing

 

Related note
3134139
CVSS
10.0

Affected system type
SAP Enterprise...
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j2 component used in SAP Enterprise Continuous Testing by Tricentis

 

Related note
3134531
CVSS
7.5

Affected system type
SAP HANA Platform
Patchday
2022-01
Released on
2021/12/24

Description
[CVE-2021-44228] Denial of Service vulnerability associated with Apache Log4j component used in XSA Cockpit

 

Related note
3131740
CVSS
9.8

Affected system type
SAP Business One
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Business One

 

Related note
3132058
CVSS
10.0

Affected system type
SAP IoT
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Cloud-to-Cloud Interoperability

 

Related note
3112710
CVSS
4.3

Affected system type
ABAP
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-42067] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
3112928
CVSS
8.7

Affected system type
ABAP
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2022-22531] Multiple vulnerabilities in F0743 Create Single Payment application of SAP S/4HANA

 

Related note
3131691
CVSS
5.5

Affected system type
Adobe LiveCycle Designer
Patchday
2022-01
Released on
2021/12/30

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP NetWeaver ABAP Server and ABAP Platform (Adobe LiveCycle Designer 11.0)

 

Related note
3135581
CVSS
6.6

Affected system type
Java
Patchday
2022-01
Released on
2022/01/11

Description
Update 3 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration

 

Related note
3136988
CVSS
10.0

Affected system type
SAP IoT
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Reference Template for enabling ingestion and persistence of time series data in Azure

 

Related note
3133005
CVSS
5.3

Affected system type
Java
Patchday
2022-01
Released on
2021/12/28

Description
Update 2 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration

 

Related note
3132177
CVSS
10.0

Affected system type
SAP Localization Hub
Patchday
2022-01
Released on
2021/12/22

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Localization Hub, digital compliance service for India

 

Related note
3124597
CVSS
6.1

Affected system type
SAP Enterprise Threat...
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2022-22529] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Threat Detection

 

Related note
3101299
CVSS
6.6

Affected system type
SAP Business One
Patchday
2022-01
Released on
2021/12/14

Description
[CVE-2021-42066] Information Disclosure vulnerability in SAP Business One

 

Related note
3132515
CVSS
10.0

Affected system type
SAP Edge Services 
Patchday
2022-01
Released on
2021/12/30

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services Cloud Edition

 

Related note
3132198
CVSS
9.8

Affected system type
SAP Landscape...
Patchday
2021-12
Released on
2021/12/20

Description
[CVE-2019-17571] Code Injection vulnerability in SAP Landscape Management

 

Related note
3131824
CVSS
8.0

Affected system type
SAP Connected Health platform
Patchday
2021-12
Released on
2021/12/20

Description
[CVE-2021-44228] Log4j Vulnerability in Connected Health Platform 2.0 - Fhirserver

 

Related note
3132074
CVSS
8.0

Affected system type
SAP Cloud for Customer
Patchday
2021-12
Released on
2021/12/23

Description
[CVE-2021-44228] Code Injection vulnerability in Cloud for Customer Lotus Notes PlugIn

 

Related note
3102769
CVSS
8.8

Affected system type
Java
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-42063] Cross-Site Scripting (XSS) vulnerability in SAP Knowledge Warehouse

 

Related note
3131047
CVSS
10.0

Affected system type
Any
Patchday
2021-12
Released on
2021/12/15

Description
[CVE-2021-44228] Central Security Note for Remote Code Execution vulnerability associated with Apache Log4j 2 component

 

Related note
3132162
CVSS
10.0

Affected system type
SAP API Management
Patchday
2021-12
Released on
2021/12/24

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP API Management (Tenant Cloning Tool)

 

Related note
3132964
CVSS
10.0

Affected system type
SAP Enable Now
Patchday
2021-12
Released on
2021/12/23

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Enable Now Manager

 

Related note
3080816
CVSS
2.4

Affected system type
ABAP
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-44233] Missing Authorization check in GRC Access Control

 

Related note
3131258
CVSS
10.0

Affected system type
SAP HANA Platform
Patchday
2021-12
Released on
2021/12/16

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP HANA XSA

 

Related note
3131397
CVSS
10.0

Affected system type
SAP HANA Platform
Patchday
2021-12
Released on
2021/12/17

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit

 

Related note
2460948
CVSS
5.3

Affected system type
ABAP
Patchday
2021-12
Released on
2021/11/23

Description
Missing Authorization Check in Vehicle Management System

 

Related note
3130578
CVSS
10.0

Affected system type
SAP BTP Cloud Foundry runtime
Patchday
2021-12
Released on
2021/12/21

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Cloud Foundry

 

Related note
3132909
CVSS
10.0

Affected system type
SAP Edge Services 
Patchday
2021-12
Released on
2021/12/24

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services On Premise Edition

 

Related note
3132204
CVSS
3.1

Affected system type
Java
Patchday
2021-12
Released on
2021/12/16

Description
Update 1 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration

 

Related note
3132822
CVSS
9.0

Affected system type
SAP HANA Platform
Patchday
2021-12
Released on
2021/12/21

Description
Update 1 to Security Note 3131397 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit

 

Related note
3132744
CVSS
10.0

Affected system type
SAP BTP Kyma runtime
Patchday
2021-12
Released on
2021/12/21

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Kyma

 

Related note
3123196
CVSS
8.4

Affected system type
ABAP
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-44235] Code Injection vulnerability in utility class for SAP NetWeaver AS ABAP

 

Related note
3051005
CVSS
3.5

Affected system type
SAP UI5
Patchday
2021-12
Released on
2021/12/14

Description
Cross-Site Scripting (XSS) Vulnerability in SAP Fiori Launchpad

 

Related note
3103677
CVSS
4.1

Affected system type
BI/BO platform
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-42061] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform (Web Intelligence)

 

Related note
2484231
CVSS
4.3

Affected system type
ABAP
Patchday
2021-12
Released on
2021/12/14

Description
Missing Authorization Check in DIMP Industry Solution (Equipment and Tools Management & Bills of Services)

 

Related note
3124094
CVSS
7.7

Affected system type
ABAP
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-44232] Directory Traversal vulnerability in SAF-T Framework

 

Related note
3113593
CVSS
7.5

Affected system type
SAP Commerce
Patchday
2021-12
Released on
2021/12/14

Description
Denial of service (DOS) in SAP Commerce

 

Related note
3121165
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-12
Released on
2021/12/14

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3130521
CVSS
9.9

Affected system type
Java
Patchday
2021-12
Released on
2021/12/16

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration

 

Related note
3109577
CVSS
9.9

Affected system type
SAP Commerce
Patchday
2021-12
Released on
2021/12/14

Description
Code Execution vulnerability in SAP Commerce, localization for China

 

Related note
2661033
CVSS
6.3

Affected system type
ABAP
Patchday
2021-12
Released on
2021/11/23

Description
Missing Authorization check in RFC enabled function modules in SRM

 

Related note
3119365
CVSS
9.9

Affected system type
ABAP
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-44231] Code Injection vulnerability in SAP ABAP Server & ABAP Platform (Translation Tools)

 

Related note
3132922
CVSS
10.0

Affected system type
SAP Edge Services 
Patchday
2021-12
Released on
2021/12/21

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Internet of Things Edge Platform

 

Related note
3107332
CVSS
6.6

Affected system type
SAP Landscape Management
Patchday
2021-12
Released on
2021/12/14

Description
Missing Authorization Check in SAP Landscape Management

 

Related note
3114134
CVSS
8.8

Affected system type
SAP Commerce
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-42064] SQL Injection vulnerability in SAP Commerce

 

Related note
3133772
CVSS
10.0

Affected system type
SAP Customer Checkout
Patchday
2021-12
Released on
2021/12/22

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Customer Checkout

 

Related note
3099776
CVSS
9.6

Affected system type
Kernel
Patchday
2021-11
Released on
2021/11/09

Description
[CVE-2021-40501] Missing Authorization check in ABAP Platform Kernel

 

Related note
2827086
CVSS
7.9

Affected system type
SAP FRP
Patchday
2021-11
Released on
2021/11/09

Description
Several security vulnerabilities in FRP 5.4.0 and FR Engine 5.4.0

 

Related note
3106859
CVSS
4.3

Affected system type
ABAP
Patchday
2021-11
Released on
2021/11/09

Description
URL Redirection vulnerability in Offer Management

 

Related note
2607126
CVSS
6.3

Affected system type
Java
Patchday
2021-11
Released on
2021/11/09

Description
Cross-Site Request Forgery vulnerability in Enterprise Services Repository of SAP Process Integration

 

Related note
3104456
CVSS
6.5

Affected system type
ABAP
Patchday
2021-11
Released on
2021/11/09

Description
[CVE-2021-42062] Missing Authorization check in SAP ERP HCM

 

Related note
3105728
CVSS
4.9

Affected system type
ABAP
Patchday
2021-11
Released on
2021/11/09

Description
[CVE-2021-40504] Leverage of Permission in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
3110328
CVSS
8.3

Affected system type
SAP Commerce
Patchday
2021-11
Released on
2021/11/09

Description
[CVE-2021-40502] Missing Authorization check in SAP Commerce

 

Related note
3080106
CVSS
6.8

Affected system type
SAP GUI / Frontend
Patchday
2021-11
Released on
2021/11/09

Description
[CVE-2021-40503] Information Disclosure in SAP GUI for Windows

 

Related note
2988956
CVSS
5.4

Affected system type
ABAP
Patchday
2021-10
Released on
2021/09/28

Description
Cross-Site Request Forgery (CSRF) vulnerability in S/4HANA OP2020, OP1909 in Import Financial Plan Data

 

Related note
2655294
CVSS
5.3

Affected system type
ABAP
Patchday
2021-10
Released on
2021/10/12

Description
Missing Authorization check in SCM BAPIs

 

Related note
3055347
CVSS
6.1

Affected system type
SAP UI5
Patchday
2021-10
Released on
2021/10/12

Description
Cross-Site Scripting (XSS) vulnerability in SAPUI5

 

Related note
3084937
CVSS
5.4

Affected system type
ABAP
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-38183] Cross-Site Scripting (XSS) vulnerability in cms Service of SAP NetWeaver

 

Related note
3100882
CVSS
6.4

Affected system type
SAP Cloud Print Manager
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-40499] Code Injection vulnerability for SAP NetWeaver Application Server for ABAP (SAP Cloud Print Manager and SAPSprint)

 

Related note
3074819
CVSS
6.7

Affected system type
SAP Business One
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-38179] Information Disclosure in SAP Business One

 

Related note
3077635
CVSS
7.8

Affected system type
SAP Success Factors
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-40498] Denial of service (DOS) in the SAP SuccessFactors Mobile Application for Android devices

 

Related note
3101406
CVSS
9.8

Affected system type
Java
Patchday
2021-10
Released on
2021/10/12

Description
Potential XML External Entity Injection Vulnerability in SAP Environmental Compliance

 

Related note
3099011
CVSS
5.3

Affected system type
ABAP
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-40495] Denial of Service (DOS) in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
2988962
CVSS
5.4

Affected system type
ABAP
Patchday
2021-10
Released on
2021/09/28

Description
Cross-Site Request Forgery (CSRF) vulnerability for S/4HANA OP2020, OP1909 in Import Financial Plan Data

 

Related note
3074693
CVSS
6.9

Affected system type
BI/BO platform
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-40500] Missing XML Validation in SAP BusinessObjects Business Intelligence Platform (Crystal Reports)

 

Related note
3087254
CVSS
4.3

Affected system type
ABAP
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-40496] Improper Access Control in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3079427
CVSS
6.5

Affected system type
SAP Business One
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-38180] CSV Injection in SAP Business One

 

Related note
3089438
CVSS
9.1

Affected system type
ABAP
Patchday
2021-10
Released on
2021/09/20

Description
Missing transaction start (AU3) entries in the Security Audit Log

 

Related note
3097887
CVSS
9.1

Affected system type
ABAP
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-38178] Improper Authorization in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3080710
CVSS
6.5

Affected system type
ABAP
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-38181] Denial of service (DOS) in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3098917
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-40497] Information Disclosure in SAP BusinessObjects Analysis (edition for OLAP)

 

Related note
2308378
CVSS
4.3

Affected system type
ABAP
Patchday
2021-09
Released on
2021/09/14

Description
Missing Authorization check in Financial Accounting

 

Related note
3084487
CVSS
9.9

Affected system type
Java
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38163] Unrestricted File Upload vulnerability in SAP NetWeaver (Visual Composer 7.0 RT)

 

Related note
3055180
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-33679] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI Workspace)

 

Related note
3069032
CVSS
6.5

Affected system type
SAP Business One
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-33685] Directory Traversal vulnerability in SAP Business One

 

Related note
3089831
CVSS
9.9

Affected system type
ABAP
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38176] SQL Injection vulnerability in SAP NZDT Mapping Table Framework

 

Related note
3075546
CVSS
4.3

Affected system type
SAP Business One
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-37532] Directory Listing Enabled in SAP Business One

 

Related note
3081888
CVSS
9.9

Affected system type
Java
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-37531] Code Injection vulnerability in SAP NetWeaver Knowledge Management (XMLForms)

 

Related note
3068582
CVSS
5.4

Affected system type
ABAP
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38164] Missing Authorization check in in SAP ERP Financial Accounting / RFOPENPOSTING_FR

 

Related note
3070138
CVSS
5.3

Affected system type
SAP Business One
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-33686] Information Disclosure in SAP Business One

 

Related note
3073891
CVSS
9.6

Affected system type
BCM platform
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-33672] Multiple vulnerabilities in SAP Contact Center

 

Related note
3060621
CVSS
6.1

Affected system type
SAP GUI / Frontend
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38150] Information disclosure in SAP Business Client

 

Related note
3087791
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38174] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3078609
CVSS
10.0

Affected system type
Java
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-37535] Missing Authorization check in SAP NetWeaver Application Server for Java (JMS Connector Service)

 

Related note
3082500
CVSS
6.5

Affected system type
ABAP
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38175] Information Disclosure in SAP Analysis for Microsoft Office

 

Related note
3069882
CVSS
4.3

Affected system type
SAP Business One
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-33688] SQL Injection vulnerability in SAP Business One

 

Related note
3068337
CVSS
3.5

Affected system type
ABAP
Patchday
2021-09
Released on
2021/09/14

Description
Reverse tabnabbing vulnerability in SAP Marketing Lead Nurture Stream

 

Related note
3051787
CVSS
7.5

Affected system type
ABAP Java HANA platform
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38177] Null Pointer Dereference vulnerability in SAP CommonCryptoLib

 

Related note
3082219
CVSS
4.8

Affected system type
Java
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-21489] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3080567
CVSS
8.9

Affected system type
Kernel
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38162] HTTP Request Smuggling in SAP Web Dispatcher

 

Related note
2675775
CVSS
6.3

Affected system type
ABAP
Patchday
2021-08
Released on
2021/08/10

Description
Switchable Authorization checks for RFC in CRM Middleware

 

Related note
3072920
CVSS
8.3

Affected system type
Java
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33703] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
2659604
CVSS
6.4

Affected system type
ABAP
Patchday
2021-08
Released on
2021/07/27

Description
Cross-Site Scripting (XSS) Vulnerability in BSP application CRM_CM

 

Related note
3063048
CVSS
4.7

Affected system type
BI/BO platform
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33697] Reverse Tabnabbing in SAP BusinessObjects Business Intelligence Platform (SAP UI5)

 

Related note
3073325
CVSS
7.0

Affected system type
SAP Business One
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33700] Missing Authentication check in SAP Business One

 

Related note
3076399
CVSS
6.1

Affected system type
Java
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33707] URL Redirection vulnerability in SAP NetWeaver (Knowledge Management)

 

Related note
3058553
CVSS
6.8

Affected system type
SAP Cloud Connector
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33695] Multiple Vulnerabilities in SAP Cloud Connector

 

Related note
3057378
CVSS
8.8

Affected system type
Kernel
Patchday
2021-08
Released on
2021/08/10

Description
Missing Authentication check in SAP Web Dispatcher

 

Related note
3067219
CVSS
7.6

Affected system type
SAP Fiori Client Android
Patchday
2021-08