Security Advisories
We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.
We hope you like it!
This time we found critical correction advisiories. We count 523 and the highest CVSS score is 10.0.
Severity
SAP© Security advisories 523
System Types
Affected SAP© system types
Affected system
type
Java
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-32247] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
BI/BO platform
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35169] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (LCM)
Affected system
type
ABAP
Patchday
2022-07
Released
on
2022/07/12
Description
Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Affected system
type
BI/BO platform
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-31591] Privilege Escalation vulnerability in SAP BusinessObjects (BW Publisher Service)
Affected system
type
SAP Business One
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35168] Denial of Service vulnerability in SAP Business One
Affected system
type
ABAP
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-32248] Missing Input Validation in Manage Checkbooks component of SAP S/4HANA
Affected system
type
Java
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35225] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
BI/BO platform
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-29619] Information Disclosure to user Administrator in SAP BusinessObjects Business Intelligence Platform 4.x
Affected system
type
BI/BO platform
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35228] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)
Affected system
type
Java
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35172] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
ABAP
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-31592] Missing Authorization check in EA-DFPS
Affected system
type
Java
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35170] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
SAP Business One
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-28771] Missing Authentication check in SAP Business One (License service API)
Affected system
type
Java
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35224] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Portal
Affected system
type
SAP 3D Visual Enterprise
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35171] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
BI/BO platform
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-32246] SQL Injection vulnerability in SAP BusinessObjects Business Intelligence Platform (Visual Difference Application)
Affected system
type
Java
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-35227] Cross-Site Scripting (XSS) vulnerability in SAP NW EP WPC
Affected system
type
ABAP
Patchday
2022-07
Released
on
2022/07/12
Description
Information Disclosure vulnerability in ABAP Platform
Affected system
type
ABAP
Patchday
2022-07
Released
on
2022/06/28
Description
Missing Authorization Check in multiple components under SAP Automotive Solutions
Affected system
type
SAP Business One
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-31593] Code Injection vulnerability in SAP Business One
Affected system
type
SAP Business One
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-32249] Information Disclosure vulnerability in SAP Business One
Affected system
type
BI/BO platform
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-31598] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects
Affected system
type
ABAP
Patchday
2022-07
Released
on
2022/07/12
Description
[CVE-2022-31597] Missing Authorization check in SAP S/4HANA(business partner extension for Spain/Slovakia)
Affected system
type
ABAP SAP Host Agent
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-29612] Server-Side Request Forgery in SAP NetWeaver, ABAP Platform and SAP Host Agent
Affected system
type
Java
Patchday
2022-06
Released
on
2022/06/14
Description
Improper Access Control check in SAP NetWeaver basicadmin and adminadapter services
Affected system
type
SAP PowerDesigner
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-31590] Potential privilege escalation in SAP PowerDesigner Proxy 16.7
Affected system
type
UI5
Patchday
2022-06
Released
on
2022/06/14
Description
Cross-Site Scripting (XSS) vulnerability in SAP Marketing Campaigns App
Affected system
type
ABAP Java HANA platform
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-29614] Privilege Escalation in SAP startservice of SAP NetWeaver AS ABAP, AS Java, ABAP Platform and HANA Database
Affected system
type
UI5
Patchday
2022-06
Released
on
2022/06/14
Description
Unsafe use of target blank in SAP Marketing Campaigns
Affected system
type
SAP Adaptive Server...
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-31594] Privilege escalation vulnerability in SAP Adaptive Server Enterprise (ASE)
Affected system
type
SAP Financial Consolidation
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-31595] Privilege escalation vulnerability in SAP Financial Consolidation
Affected system
type
SAP...
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-29618] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Development Infrastructure (Design Time Repository)
Affected system
type
Java
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-29615] Multiple vulnerabilities associated with Apache log4j 1.x component in SAP NetWeaver Developer Studio (NWDS)
Affected system
type
ABAP
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-31589] Segregation of Duty vulnerability in IL FI-AP File from SHAAM program.
Affected system
type
SAP 3D Visual Enterprise
Patchday
2022-06
Released
on
2022/06/14
Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
SAProuter
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-27668] Improper Access Control of SAProuter for SAP NetWeaver and ABAP Platform
Affected system
type
ABAP
Patchday
2022-06
Released
on
2022/06/14
Description
Missing Authorization check in SAP ERP HCM
Affected system
type
BI/BO platform
Patchday
2022-05
Released
on
2022/05/10
Description
[CVE-2022-28214] Central Management Server Information Disclosure in Business Intelligence Update
Affected system
type
Kernel
Patchday
2022-05
Released
on
2022/05/10
Description
[CVE-2022-27656] Cross-Site Scripting (XSS) vulnerability in administration UI of SAP Webdispatcher and SAP Netweaver AS for ABAP and Java (ICM)
Affected system
type
ABAP
Patchday
2022-05
Released
on
2022/05/10
Description
[CVE-2022-29610] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
Affected system
type
ABAP
Patchday
2022-05
Released
on
2022/05/10
Description
Cross-Site Request Forgery (CSRF) vulnerability in F0673 Approve Bank Payments back-end
Affected system
type
ABAP
Patchday
2022-05
Released
on
2022/05/10
Description
[CVE-2022-29613] Information Disclosure vulnerability in SAP Employee Self Service(Fiori My Leave Request)
Affected system
type
SAP Business One Cloud
Patchday
2022-05
Released
on
2022/05/10
Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in in SAP Business One Cloud
Affected system
type
SAP Host AgentKernel
Patchday
2022-05
Released
on
2022/05/10
Description
[CVE-2022-29616] Memory Corruption vulnerability in SAP Host Agent, SAP NetWeaver and ABAP Platform
Affected system
type
ABAP
Patchday
2022-05
Released
on
2022/05/10
Description
[CVE-2022-29611] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
SAP Host Agent
Patchday
2022-05
Released
on
2022/05/10
Description
[CVE-2022-28774] Information Disclosure vulnerability in SAP Host Agent logfile
Affected system
type
UI5
Patchday
2022-05
Released
on
2022/05/10
Description
Cross-Site Request Forgery (CSRF) vulnerability in F0673 Approve Bank Payments front-end
Affected system
type
ABAP
Patchday
2022-05
Released
on
2022/05/10
Description
Missing Authorization check for UI5 flexibility key user functionality
Affected system
type
SAP Commerce
Patchday
2022-04
Released
on
2022/04/12
Description
Privilege escalation vulnerability in Apache Tomcat server component of SAP Commerce
Affected system
type
BI/BO platform
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-27671] CSRF token visible in one of the URL in SAP Business Intelligence Platform.
Affected system
type
Java
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-28217] Missing XML Validation vulnerability in SAP NW EP WPC
Affected system
type
BI/BO platform
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-28213] Missing XML Validation vulnerability in SAP BusinessObjects Business Intelligence Platform (dswsbobje - SOAP Web services)
Affected system
type
BI/BO platform
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-22541] Information Disclosure vulnerability in SAP BusinessObjects Platform
Affected system
type
Java
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-26105] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
Sybase
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-27670] Denial of service (DOS) in SQL Anywhere
Affected system
type
SAP 3D Visual Enterprise
Patchday
2022-04
Released
on
2022/04/12
Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
SAP HANA Platform
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP HANA Extended Application Services
Affected system
type
BI/BO platform
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-28216] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI Workspace)
Affected system
type
Adobe LiveCycle Designer
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2021-44832] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP NetWeaver ABAP Server and ABAP Platform (Adobe LiveCycle Designer 11.0)
Affected system
type
Kernel
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-28772]Denial of service (DOS) in SAP Web Dispatcher and SAP Netweaver (Internet Communication Manager)
Affected system
type
ABAP
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-28215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform
Affected system
type
SAP Commerce
Patchday
2022-04
Released
on
2022/04/18
Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Commerce
Affected system
type
SAP GUI / Frontend
Patchday
2022-04
Released
on
2022/04/12
Description
Information Disclosure vulnerability in SAP GUI for Windows
Affected system
type
BI/BO platform
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-27667] Information Disclosure vulnerability in CMC
Affected system
type
Kernel
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-28773] Denial of service (DOS) in SAP Web Dispatcher and SAP Netweaver (Internet Communication Manager)
Affected system
type
SAP Solution Manager...
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-27657] Directory Traversal vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)
Affected system
type
Java
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-27669] Missing Authentication check in XML Data Archiving Service
Affected system
type
Java
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in PowerDesigner Web (up to including 16.7 SP05 PL01)
Affected system
type
ABAP
Patchday
2022-04
Released
on
2022/04/12
Description
Multiple Vulnerabilities in URI.js bundled with SAPUI5
Affected system
type
SAP Innovation Management
Patchday
2022-04
Released
on
2022/03/28
Description
[CVE-2022-27658] Missing authorization check in SAP Innovation Management
Affected system
type
Java
Patchday
2022-04
Released
on
2022/04/12
Description
Update 1 to Security Note 3022622 - [CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence
Affected system
type
Any
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-22965] Central Security Note for Remote Code Execution vulnerability associated with Spring Framework
Affected system
type
SAP Customer Checkout
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Checkout
Affected system
type
ABAP
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-28770] Cross-Site Scripting (XSS) vulnerability in SAPUI5 (vbm library)
Affected system
type
ABAP
Patchday
2022-04
Released
on
2022/04/12
Description
Enable CSP support for OP1909 in SAP CRM WebClient UI
Affected system
type
SAP Customer...
Patchday
2022-04
Released
on
2022/04/14
Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Profitability Analytics
Affected system
type
ABAP
Patchday
2022-03
Released
on
2022/03/22
Description
Missing authorization check in S/4HANA finance for advanced payment management
Affected system
type
Java
Patchday
2022-03
Released
on
2022/03/08
Description
[CVE-2022-26103] Information Disclosure vulnerability in SAP NetWeaver(Real Time Messaging Framework)
Affected system
type
SAP Solution Manager...
Patchday
2022-03
Released
on
2022/03/08
Description
[CVE-2022-24399] Cross-Site Scripting (XSS) vulnerability in SAP Focused Run (Real User Monitoring)
Affected system
type
SAPCAR
Patchday
2022-03
Released
on
2022/03/08
Description
[CVE-2022-26100] Denial of service (DOS) in SAPCAR
Affected system
type
SAP Solution Manager...
Patchday
2022-03
Released
on
2022/03/08
Description
[CVE-2022-22547] Information Disclosure vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)
Affected system
type
BI/BO platform
Patchday
2022-03
Released
on
2022/03/08
Description
[CVE-2022-24398] Information Disclosure vulnerability in SAP Business Objects Business Intelligence Platform
Affected system
type
ABAP
Patchday
2022-03
Released
on
2022/03/08
Description
[CVE-2022-26102] Missing authorization check in SAP NetWeaver Application Server for ABAP
Affected system
type
SAP Work Manager
Patchday
2022-03
Released
on
2022/03/08
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Work Manager
Affected system
type
ABAP
Patchday
2022-03
Released
on
2022/03/08
Description
[CVE-2022-26101] Cross-Site Scripting (XSS) vulnerability in SAP Fiori launchpad
Affected system
type
Java
Patchday
2022-03
Released
on
2022/03/08
Description
[CVE-2022-24395] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
Java
Patchday
2022-03
Released
on
2013/08/13
Description
Directory traversal in Web Container
Affected system
type
Java
Patchday
2022-03
Released
on
2022/03/08
Description
[CVE-2022-24397] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
SAP Financial Consolidation
Patchday
2022-03
Released
on
2022/03/08
Description
[CVE-2022-26104] Missing Authorization check in SAP Financial Consolidation
Affected system
type
SAP Solution Manager...
Patchday
2022-03
Released
on
2022/03/08
Description
[CVE-2022-24396] Missing Authentication check in SAP Focused Run (Simple Diagnostics Agent 1.0)
Affected system
type
SAP Adaptive Server...
Patchday
2022-02
Released
on
2022/02/08
Description
[CVE-2022-22528] Information Disclosure in SAP Adaptive Server Enterprise
Affected system
type
BI/BO platform
Patchday
2022-02
Released
on
2022/02/08
Description
[CVE-2022-22546] XSS vulnerability in SAP Business Objects Web Intelligence (BI Launchpad)
Affected system
type
Kernel
Patchday
2022-02
Released
on
2022/02/08
Description
[CVE-2022-22532] HTTP Request Smuggling in SAP NetWeaver Application Server Java
Affected system
type
ABAP
Patchday
2022-02
Released
on
2022/02/08
Description
[CVE-2022-22545] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Affected system
type
Kernel
Patchday
2022-02
Released
on
2022/02/08
Description
[CVE-2022-22543] Denial of service (DOS) in SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel)
Affected system
type
Java
Patchday
2022-02
Released
on
2022/02/08
Description
[CVE-2022-22544] Missing segregation of duties in SAP Solution Manager Diagnostics Root Cause Analysis Tools
Affected system
type
SAP 3D Visual Enterprise
Patchday
2022-02
Released
on
2022/02/08
Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
SAP Commerce
Patchday
2022-02
Released
on
2022/02/08
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Commerce
Affected system
type
ABAP
Patchday
2022-02
Released
on
2022/02/08
Description
[CVE-2022-22534] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver
Affected system
type
ABAP
Patchday
2022-02
Released
on
2022/02/08
Description
[CVE-2022-22535] Missing Authorization check in SAP ERP HCM
Affected system
type
ABAP
Patchday
2022-02
Released
on
2019/04/09
Description
Switchable Authorization checks for RFC BCA_DIM_RESET_TRIGGER_TABLE in Loans (FI-CAX-FS)
Affected system
type
SAP Data Intelligence
Patchday
2022-02
Released
on
2022/01/18
Description
Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Data Intelligence 3 (on-premise)
Affected system
type
ABAP
Patchday
2022-02
Released
on
2022/01/25
Description
Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver AS ABAP within Web Dynpro ABAP
Affected system
type
ABAP
Patchday
2022-02
Released
on
2022/02/08
Description
[CVE-2022-22542] Information Disclosure vulnerability in SAP S/4HANA (Supplier Factsheet and Enterprise Search for Business Partner, Supplier and Customer)
Affected system
type
Kernel
Patchday
2022-02
Released
on
2022/02/08
Description
[CVE-2022-22536] Request smuggling and request concatenation in SAP NetWeaver, SAP Content Server and SAP Web Dispatcher
Affected system
type
ABAP
Patchday
2022-02
Released
on
2022/02/08
Description
[CVE-2022-22540] SQL Injection vulnerability in SAP NetWeaver AS ABAP (Workplace Server)
Affected system
type
None
Patchday
2022-02
Released
on
2022/02/08
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Dynamic Authorization Management
Affected system
type
SAP Edge ServicesÂ
Patchday
2022-01
Released
on
2021/12/30
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services Cloud Edition
Affected system
type
SAP Enterprise Threat...
Patchday
2022-01
Released
on
2022/01/11
Description
[CVE-2022-22529] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Threat Detection
Affected system
type
SAP Localization Hub
Patchday
2022-01
Released
on
2021/12/22
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Localization Hub, digital compliance service for India
Affected system
type
SAP Digital...
Patchday
2022-01
Released
on
2022/01/11
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Digital Manufacturing Cloud for Edge Computing
Affected system
type
SAP Enterprise...
Patchday
2022-01
Released
on
2022/01/11
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j2 component used in SAP Enterprise Continuous Testing by Tricentis
Affected system
type
SAP IoT
Patchday
2022-01
Released
on
2022/01/11
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Reference Template for enabling ingestion and persistence of time series data in Azure
Affected system
type
Java
Patchday
2022-01
Released
on
2022/01/11
Description
Update 3 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration
Affected system
type
Java
Patchday
2022-01
Released
on
2021/12/28
Description
Update 2 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration
Affected system
type
SAP Business One
Patchday
2022-01
Released
on
2021/12/14
Description
[CVE-2021-42066] Information Disclosure vulnerability in SAP Business One
Affected system
type
ABAP
Patchday
2022-01
Released
on
2022/01/11
Description
[CVE-2021-42067] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2022-01
Released
on
2022/01/11
Description
[CVE-2022-22531] Multiple vulnerabilities in F0743 Create Single Payment application of SAP S/4HANA
Affected system
type
SAP IoT
Patchday
2022-01
Released
on
2022/01/11
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Cloud-to-Cloud Interoperability
Affected system
type
SAP HANA Platform
Patchday
2022-01
Released
on
2021/12/24
Description
[CVE-2021-44228] Denial of Service vulnerability associated with Apache Log4j component used in XSA Cockpit
Affected system
type
SAP Business One
Patchday
2022-01
Released
on
2022/01/11
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Business One
Affected system
type
Adobe LiveCycle Designer
Patchday
2022-01
Released
on
2021/12/30
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP NetWeaver ABAP Server and ABAP Platform (Adobe LiveCycle Designer 11.0)
Affected system
type
SAP Business One
Patchday
2022-01
Released
on
2022/01/11
Description
[CVE-2021-44234] Information Disclosure vulnerability in SAP Business One
Affected system
type
SAP BTP Cloud Foundry runtime
Patchday
2021-12
Released
on
2021/12/21
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Cloud Foundry
Affected system
type
SAP BTP Kyma runtime
Patchday
2021-12
Released
on
2021/12/21
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Kyma
Affected system
type
SAP Edge ServicesÂ
Patchday
2021-12
Released
on
2021/12/21
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Internet of Things Edge Platform
Affected system
type
SAP HANA Platform
Patchday
2021-12
Released
on
2021/12/21
Description
Update 1 to Security Note 3131397 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit
Affected system
type
SAP Landscape...
Patchday
2021-12
Released
on
2021/12/20
Description
[CVE-2019-17571] Code Injection vulnerability in SAP Landscape Management
Affected system
type
Java
Patchday
2021-12
Released
on
2021/12/16
Description
Update 1 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration
Affected system
type
SAP Edge ServicesÂ
Patchday
2021-12
Released
on
2021/12/24
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services On Premise Edition
Affected system
type
SAP Customer Checkout
Patchday
2021-12
Released
on
2021/12/22
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Customer Checkout
Affected system
type
SAP HANA Platform
Patchday
2021-12
Released
on
2021/12/16
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP HANA XSA
Affected system
type
SAP HANA Platform
Patchday
2021-12
Released
on
2021/12/17
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit
Affected system
type
ABAP
Patchday
2021-12
Released
on
2021/11/23
Description
Missing Authorization Check in Vehicle Management System
Affected system
type
Java
Patchday
2021-12
Released
on
2021/12/14
Description
[CVE-2021-42063] Cross-Site Scripting (XSS) vulnerability in SAP Knowledge Warehouse
Affected system
type
SAP API Management
Patchday
2021-12
Released
on
2021/12/24
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP API Management (Tenant Cloning Tool)
Affected system
type
ABAP
Patchday
2021-12
Released
on
2021/12/14
Description
[CVE-2021-44235] Code Injection vulnerability in utility class for SAP NetWeaver AS ABAP
Affected system
type
ABAP
Patchday
2021-12
Released
on
2021/12/14
Description
[CVE-2021-44232] Directory Traversal vulnerability in SAF-T Framework
Affected system
type
ABAP
Patchday
2021-12
Released
on
2021/11/23
Description
Missing Authorization check in RFC enabled function modules in SRM
Affected system
type
ABAP
Patchday
2021-12
Released
on
2021/12/14
Description
[CVE-2021-44231] Code Injection vulnerability in SAP ABAP Server & ABAP Platform (Translation Tools)
Affected system
type
ABAP
Patchday
2021-12
Released
on
2021/12/14
Description
[CVE-2021-44233] Missing Authorization check in GRC Access Control
Affected system
type
SAP UI5
Patchday
2021-12
Released
on
2021/12/14
Description
Cross-Site Scripting (XSS) Vulnerability in SAP Fiori Launchpad
Affected system
type
BI/BO platform
Patchday
2021-12
Released
on
2021/12/14
Description
[CVE-2021-42061] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform (Web Intelligence)
Affected system
type
ABAP
Patchday
2021-12
Released
on
2021/12/14
Description
Missing Authorization Check in DIMP Industry Solution (Equipment and Tools Management & Bills of Services)
Affected system
type
Java
Patchday
2021-12
Released
on
2021/12/16
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration
Affected system
type
SAP Commerce
Patchday
2021-12
Released
on
2021/12/14
Description
Code Execution vulnerability in SAP Commerce, localization for China
Affected system
type
SAP Landscape Management
Patchday
2021-12
Released
on
2021/12/14
Description
Missing Authorization Check in SAP Landscape Management
Affected system
type
SAP Commerce
Patchday
2021-12
Released
on
2021/12/14
Description
[CVE-2021-42064] SQL Injection vulnerability in SAP Commerce
Affected system
type
SAP 3D Visual Enterprise
Patchday
2021-12
Released
on
2021/12/14
Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
SAP Connected Health platform
Patchday
2021-12
Released
on
2021/12/20
Description
[CVE-2021-44228] Log4j Vulnerability in Connected Health Platform 2.0 - Fhirserver
Affected system
type
Any
Patchday
2021-12
Released
on
2021/12/15
Description
[CVE-2021-44228] Central Security Note for Remote Code Execution vulnerability associated with Apache Log4j 2 component
Affected system
type
SAP Enable Now
Patchday
2021-12
Released
on
2021/12/23
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Enable Now Manager
Affected system
type
SAP Commerce
Patchday
2021-12
Released
on
2021/12/14
Description
Denial of service (DOS) in SAP Commerce
Affected system
type
SAP Cloud for Customer
Patchday
2021-12
Released
on
2021/12/23
Description
[CVE-2021-44228] Code Injection vulnerability in Cloud for Customer Lotus Notes PlugIn
Affected system
type
Kernel
Patchday
2021-11
Released
on
2021/11/09
Description
[CVE-2021-40501] Missing Authorization check in ABAP Platform Kernel
Affected system
type
ABAP
Patchday
2021-11
Released
on
2021/11/09
Description
[CVE-2021-40504] Leverage of Permission in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
SAP Commerce
Patchday
2021-11
Released
on
2021/11/09
Description
[CVE-2021-40502] Missing Authorization check in SAP Commerce
Affected system
type
SAP FRP
Patchday
2021-11
Released
on
2021/11/09
Description
Several security vulnerabilities in FRP 5.4.0 and FR Engine 5.4.0
Affected system
type
ABAP
Patchday
2021-11
Released
on
2021/11/09
Description
[CVE-2021-42062] Missing Authorization check in SAP ERP HCM
Affected system
type
ABAP
Patchday
2021-11
Released
on
2021/11/09
Description
URL Redirection vulnerability in Offer Management
Affected system
type
SAP GUI / Frontend
Patchday
2021-11
Released
on
2021/11/09
Description
[CVE-2021-40503] Information Disclosure in SAP GUI for Windows
Affected system
type
Java
Patchday
2021-11
Released
on
2021/11/09
Description
Cross-Site Request Forgery vulnerability in Enterprise Services Repository of SAP Process Integration
Affected system
type
SAP Cloud Print Manager
Patchday
2021-10
Released
on
2021/10/12
Description
[CVE-2021-40499] Code Injection vulnerability for SAP NetWeaver Application Server for ABAP (SAP Cloud Print Manager and SAPSprint)
Affected system
type
SAP Business One
Patchday
2021-10
Released
on
2021/10/12
Description
[CVE-2021-38179] Information Disclosure in SAP Business One
Affected system
type
ABAP
Patchday
2021-10
Released
on
2021/10/12
Description
Missing Authorization check in SCM BAPIs