We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.
We hope you like it!
This time we found critical correction advisiories. We count 867 and the highest CVSS score is 10.0.
Severity
SAP© Security advisories 867
System Types
Affected SAP© system types
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-45279] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP(CRM Blueprint Application Builder Panel)
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-45284] Missing authorization check in SAP Student Life Cycle Management (SLcM)
Affected system
type
JAVA
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-44120] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
JAVA
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-45280] Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver AS Java (Logon Application)
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-44112] Missing Authorization check in SAP for Oil & Gas (Transportation and Distribution)
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[Multiple CVEs] Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
JAVA
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-45283] Information disclosure vulnerability in SAP NetWeaver AS for Java (Destination Service)
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-44114] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-45286] Missing Authorization check in SAP Production and Revenue Accounting (Tobin interface)
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-42378] Cross-Site Scripting (XSS) in eProcurement on S/4HANA
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-41729] Information Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer)
Affected system
type
SAP BusinessObjects...
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-45281] DLL hijacking vulnerability in SAP BusinessObjects Business Intelligence Platform
Affected system
type
SAP Commerce Cloud
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2013-3587] Information Disclosure vulnerability in SAP Commerce Cloud
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-44113] Information Disclosure vulnerability in the SAP Business Warehouse (BEx Analyzer)
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-41728] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
SAP Commerce Cloud
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-33003] Information Disclosure Vulnerability in SAP Commerce Cloud
Affected system
type
Sybase platform
Patchday
2024-08
Released
on
2024/08/13
Description
[Multiple CVEs] Multiple vulnerabilities in SAP Replication Server (FOSS)
Affected system
type
SAP Fiori
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-41736] Information Disclosure vulnerability in SAP Permit to Work
Affected system
type
BI/BO platform
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-41730] Missing Authentication check in SAP BusinessObjects Business Intelligence Platform
Affected system
type
SAP Build Apps
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-29415] Server-Side Request Forgery vulnerability in applications built with SAP Build Apps
Affected system
type
SAP Fiori
Patchday
2024-08
Released
on
2024/07/23
Description
[CVE-2023-30533] Prototype Pollution in SAP S/4 HANA (Manage Supply Protection)
Affected system
type
ABAP
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-41734] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-42373] Missing Authorization Check in SAP Student Life Cycle Management (SLcM)
Affected system
type
Java
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-42374] XML injection in SAP BEx Web Java Runtime Export Web Service
Affected system
type
SAP Commerce
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-41733] Information Disclosure Vulnerability in SAP Commerce
Affected system
type
ABAP
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-41732] Improper Access Control in SAP Netweaver Application Server ABAP
Affected system
type
Kernel / Web Dispatcher
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-33005] Missing Authorization check in SAP NetWeaver Application Server (ABAP and Java),SAP Web Dispatcher and SAP Content Server.
Affected system
type
BI/BO platform
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-42375] Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform
Affected system
type
ABAP
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-42376] Multiple Missing Authorization Check vulnerabilities in SAP Shared Service Framework
Affected system
type
ABAP
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-39591] Missing Authorization check in SAP Document Builder
Affected system
type
ABAP
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-41737] Server-Side Request Forgery (SSRF) in SAP CRM ABAP (Insights Management)
Affected system
type
SAP Commerce
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-41735] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice
Affected system
type
ABAP
Patchday
2024-08
Released
on
2024/08/27
Description
[CVE-2024-44121] Information Disclosure in SAP S/4 HANA (Statutory Reports)
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-37171] Server-Side Request Forgery (SSRF) in SAP Transportation Management (Collaboration Portal)
Affected system
type
SAP Enable Now
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34692] Unrestricted File upload vulnerability in SAP Enable Now
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39599] Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
SAP Landscape...
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39593] Information Disclosure vulnerability in SAP Landscape Management
Affected system
type
SAP CRM UI
Patchday
2024-07
Released
on
2024/07/09
Description
[Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI)
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39592] Missing Authorization check in SAP PDCE
Affected system
type
SAP Commerce
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39597] Improper Authorization Checks on Early Login Composable Storefront B2B sites of SAP Commerce
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34689] Allowlisting of callback-URLs in SAP Business Workflow (WebFlow Services)
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-37172] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39594] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Business Warehouse - Business Planning and Simulation
Affected system
type
SAP Enable Now
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39596] Missing Authorization check vulnerability in SAP Enable Now
Affected system
type
Java
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34685] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Knowledge Management XMLEditor
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34689] Prerequisite for Security Note 3458789
Affected system
type
SAP GUI
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39600] Information Disclosure vulnerability in SAP GUI for Windows
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34689] Server-Side Request Forgery in SAP Business Workflow (WebFlow Services)
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34691] Missing Authorization check in SAP S/4HANA (Manage Incoming Payment Files)
Affected system
type
BI/BO platform
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34684] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Scheduling)
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34683] Unrestricted file upload in SAP Document Builder (HTTP service)
Affected system
type
Java
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34688] Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-37176] Missing Authorization check in SAP BW/4HANA Transformation and DTP
Affected system
type
SAP Financial Consolidation
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-37177] Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34686] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Affected system
type
Java
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-28164] Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures)
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-33001] Denial of service (DOS) in SAP NetWeaver and ABAP platform
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34690] Missing Authorization check in SAP Student Life Cycle Management (SLcM)
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33009] SQL injection vulnerability in SAP Global Label Management (GLM)
Affected system
type
Sybase platform
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33008] Memory Corruption vulnerability in SAP Replication Server
Affected system
type
SAP Commerce Cloud
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2019-17495] Multiple vulnerabilities in SAP CX Commerce
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-34687] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application server for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[Multiple CVEs] Missing Authorization Checks in SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)
Affected system
type
BI/BO platform
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33004] Insecure Storage vulnerability in SAP BusinessObjects Business Intelligence Platform (Webservices)
Affected system
type
BI/BO platform
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-28165] Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33002] Cross-Site Scripting (XSS) Vulnerability in SAP S/4HANA (Document Service Handler for DPS)
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33006] File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33000] Missing Authorization check in SAP Bank Account Management
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-32733] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-32731] Missing Authorization check in SAP My Travel Requests
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33007] Client-side script execution vulnerability in SAP UI5(PDFViewer)
Affected system
type
ABAP
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-30216] Missing Authorization check in SAP S/4 HANA (Cash Management)
Affected system
type
Java
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-27899] Security misconfiguration vulnerability in SAP NetWeaver AS Java User Management Engine
Affected system
type
Kernel
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-30218] Denial of service (DOS) vulnerability in SAP NetWeaver AS ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-28167] Missing Authorization check in SAP Group Reporting Data Collection (Enter Package Data)
Affected system
type
SAP Edge Integration
Patchday
2024-04
Released
on
2024/04/09
Description
Stack overflow vulnerability on the component images of SAP Integration Suite (EDGE INTEGRATION CELL)
Affected system
type
ABAP
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-27901] Directory Traversal vulnerability in SAP Asset Accounting
Affected system
type
SAP Business Connector
Patchday
2024-04
Released
on
2024/04/09
Description
[Multiple CVEs] Cross-Site Scripting (XSS) vulnerabilities in SAP Business Connector
Affected system
type
ABAP
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-30217] Missing Authorization check in SAP S/4 HANA (Cash Management)
Affected system
type
Java
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-27898] Server-Side Request Forgery in SAP NetWeaver (tc~esi~esp~grmg~wshealthcheck~ear)
Affected system
type
BI/BO platform
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-25646] Information Disclosure vulnerability in SAP BusinessObjects Web Intelligence
Affected system
type
ABAP
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-22133] Improper Access Control in SAP Fiori Front End Server
Affected system
type
ABAP
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-27900]Missing Authorization check in SAP ABAP Platform
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-22127] Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)
Affected system
type
HANA platform
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2023-44487 ] Denial of service (DOS) in SAP HANA XS Classic and HANA XS Advanced
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-28163] Information Disclosure vulnerability in SAP NetWeaver Process Integration (Support Web Pages)
Affected system
type
SAP Build Apps
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2019-10744] Code Injection vulnerability in applications built with SAP Build Apps
Affected system
type
Kernel
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-27902] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP, applications based on SAPGUI for HTML (WebGUI)
Affected system
type
BI/BO platform
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2023-50164] Path Traversal Vulnerability in SAP BusinessObjects Business Intelligence Platform (Central Management Console)
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-25644] Information Disclosure vulnerability in SAP NetWeaver (WSRM)
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-25645] Information Disclosure vulnerability in SAP NetWeaver (Enterprise Portal)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22130] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Affected system
type
SAP Enable Now
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22129] Cross-Site Scripting (XSS) vulnerability in SAP Companion
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24739] Missing authorization check in SAP Bank Account Management
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Affected system
type
SAP Cloud Connector
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-25642] Improper Certificate Validation in SAP Cloud Connector
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22128] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Business Client for HTML
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/01
Description
[CVE-2024-24741] Missing Authorization check in SAP Master Data Governance Material
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22131] Code Injection vulnerability in SAP ABA (Application Basis)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22132] Code Injection vulnerability in SAP IDES Systems
Affected system
type
Kernel
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24740] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (SAP Kernel)
Affected system
type
Java
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application)
Affected system
type
Java
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24743] XXE vulnerability in SAP NetWeaver AS Java (Guided Procedures)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-25643] Missing authorization check in SAP Fiori app ("My Overtime Requests")
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21736] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21735] Improper Authorization check in SAP LT Replication Server
Affected system
type
Kernel
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2023-44487] Denial of service (DOS) in SAP Web Dispatcher, SAP NetWeaver Application server ABAP, and ABAP Platform
Affected system
type
BTP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA
Affected system
type
SAP Marketing
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21734] URL Redirection vulnerability in SAP Marketing (Contacts App)
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21738] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform
Affected system
type
Kernel / Web Dispatcher
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-22124] Information Disclosure vulnerability in SAP NetWeaver Internet Communication Manager
Affected system
type
SAP Edge Integration
Patchday
2024-01
Released
on
2024/01/09
Description
[Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell
Affected system
type
SAP GUI / Frontend
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-22125] Information Disclosure vulnerability in Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge)
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21737] Code Injection vulnerability in SAP Application Interface Framework (File Adapter)
Affected system
type
ABAP
Patchday
2023-12
Released
on
2023/12/12
Description
[CVE-2023-49581] SQL Injection vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2023-12
Released
on
2023/12/12
Description
Update 1 to 3350297 - [CVE-2023-36922] OS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)
Affected system
type
SAP GUI / Frontend
Patchday
2023-12
Released
on
2023/12/12
Description
[CVE-2023-49580] Information disclosure vulnerability in SAP GUI for WIndows and SAP GUI for Java
Affected system
type
SAP UI5
Patchday
2023-12
Released
on
2023/12/12
Description
[CVE-2023-49584] Client-Side Desynchronization vulnerability in SAP Fiori Launchpad
Affected system
type
BTP
Patchday
2023-12
Released
on
2023/12/12
Description
[Multiple CVEs] Escalation of Privileges in SAP Business Technology Platform (BTP) Security Services Integration Libraries
Affected system
type
Android SDK
Patchday
2023-12
Released
on
2023/12/12
Description
[CVE-2023-6542] Missing Authorization Check in SAP EMARSYS SDK ANDROID
Affected system
type
ABAP
Patchday
2023-12
Released
on
2023/12/12
Description
[CVE-2023-49587] Command Injection vulnerability in SAP Solution Manager
Affected system
type
ABAP
Patchday
2023-12
Released
on
2023/12/12
Description
[CVE-2023-49577] Cross-Site Scripting (XSS) vulnerability in the SAP HCM (SMART PAYE solution)
Affected system
type
ABAP
Patchday
2023-12
Released
on
2023/12/12
Description
Denial of service (DoS) vulnerability in JSZip library bundled within SAPUI5
Affected system
type
SAP Commerce
Patchday
2023-12
Released
on
2023/12/12
Description
[CVE-2023-42481] Improper Access Control vulnerability in SAP Commerce Cloud
Affected system
type
BI/BO platform
Patchday
2023-12
Released
on
2023/12/12
Description
[CVE-2023-42478] Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
Affected system
type
BI/BO platform
Patchday
2023-12
Released
on
2023/12/12
Description
[CVE-2023-42476] Cross Site Scripting vulnerability in SAP BusinessObjects Web Intelligence
Affected system
type
ABAP
Patchday
2023-12
Released
on
2023/12/12
Description
[CVE-2023-49058] Directory Traversal vulnerability in SAP Master Data Governance
Affected system
type
Java
Patchday
2023-12
Released
on
2023/12/12
Description
[CVE-2023-42479] Cross-Site Scripting (XSS) vulnerability in SAP Biller Direct
Affected system
type
SAP Cloud Connector
Patchday
2023-12
Released
on
2023/12/12
Description
[CVE-2023-49578] Denial of service (DOS) in SAP Cloud Connector
Affected system
type
Java
Patchday
2023-11
Released
on
2023/11/14
Description
[CVE-2023-42480] Information Disclosure in NetWeaver AS Java Logon
Affected system
type
SAP Business One
Patchday
2023-11
Released
on
2023/11/14
Description
[CVE-2023-31403] Improper Access Control vulnerability in SAP Business One product installation
Affected system
type
Kernel
Patchday
2023-11
Released
on
2023/11/14
Description
[CVE-2023-41366] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Affected system
type
BI/BO platform
Patchday
2023-10
Released
on
2023/10/10
Description
[CVE-2023-42474] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Web Intelligence
Affected system
type
Java
Patchday
2023-10
Released
on
2023/10/10
Description
Update 1 to Security Note 3324732: [CVE-2023-31405] Log Injection vulnerability in SAP NetWeaver AS for Java (Log Viewer)
Affected system
type
Java
Patchday
2023-10
Released
on
2023/10/26
Description
[CVE-2023-42477] Server-Side Request Forgery in SAP NetWeaver AS Java (GRMG Heartbeat application)
Affected system
type
ABAP
Patchday
2023-10
Released
on
2023/10/10
Description
[CVE-2023-42475] Information Disclosure Vulnerability in Statutory Reporting
Affected system
type
SAP PowerDesigner
Patchday
2023-10
Released
on
2023/10/10
Description
[CVE-2023-40310] Missing XML Validation vulnerability in SAP PowerDesigner Client (BPMN2 import)
Affected system
type
SAP Business One
Patchday
2023-10
Released
on
2023/10/10
Description
[CVE-2023-41365] Information Disclosure vulnerability in SAP Business One (B1i)
Affected system
type
ABAP
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-40625] Missing Authorization check in Manage Purchase Contracts App
Affected system
type
ABAP
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-41369] External Entity Loop vulnerability in SAP S/4HANA (Create Single Payment application)
Affected system
type
Java
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-41367] Missing Authentication check in SAP NetWeaver (Guided Procedures)
Affected system
type
BI/BO platform
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-42472] Insufficient File type validation in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)
Affected system
type
ABAP
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-40624] Code Injection vulnerability in SAP NetWeaver AS ABAP (applications based on Unified Rendering)
Affected system
type
BI/BO platform
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-37489] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Version Management System)
Affected system
type
Java
Patchday
2023-09
Released
on
2023/09/12
Description
Denial of service (DOS) vulnerability due to the usage of vulnerable version of Commons File Upload in SAP Quotation Management Insurance (FS-QUO)
Affected system
type
SAP BI
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-40622] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management)
Affected system
type
Kernel
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-40308] Memory Corruption vulnerability in SAP CommonCryptoLib
Affected system
type
BI/BO platform
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-40623] Arbitrary File Delete via Directory Junction in SAP BusinessObjects Suite(installer)
Affected system
type
PowerDesigner
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-40621] Code Injection vulnerability in SAP PowerDesigner Client
Affected system
type
ABAP
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-41368] Insecure Direct Object Reference (IDOR) vulnerability in SAP S/4HANA (Manage checkbook apps)
Affected system
type
Kernel, HANA...
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-40309] Missing Authorization check in SAP CommonCryptoLib
Affected system
type
SAP Business One
Patchday
2023-08
Released
on
2023/08/08
Description
[CVE-2023-33993] SQL Injection vulnerability in SAP Business One (B1i Layer)
Affected system
type
SAP Host Agent
Patchday
2023-08
Released
on
2023/08/08
Description
[CVE-2023-36926] Information disclosure vulnerability in SAP Host Agent
Affected system
type
SAP UI5
Patchday
2023-08
Released
on
2023/08/08
Description
Cross-Site Scripting (XSS) vulnerabilities in jQuery-UI library bundled with SAPUI5
Affected system
type
ABAP
Patchday
2023-08
Released
on
2023/08/08
Description
[CVE-2023-40306] URL Redirection vulnerability in SAP S/4HANA (Manage Catalog Items and Cross-Catalog search)
Affected system
type
SAP PowerDesigner
Patchday
2023-08
Released
on
2023/08/08
Description
[CVE-2023-36923] Code Injection vulnerability in SAP PowerDesigner
Affected system
type
ABAP
Patchday
2023-08
Released
on
2023/08/08
Description
[CVE-2023-37492] Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform