Security Advisories  

We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.

The user interface, is designed to be as intuitive as possible but we'd love to hear your feedback and opinions.
We hope you like it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 771 and the highest CVSS score is 10.0.

 

 Severity
SAP© Security advisories 771
 System Types
Affected SAP© system types

 

Related note
3410875
CVSS
7.6

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22130] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)

 

Related note
3426111
CVSS
8.6

Affected system type
Java
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-24743] XXE vulnerability in SAP NetWeaver AS Java (Guided Procedures)

 

Related note
3158455
CVSS
4.1

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-24742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)

 

Related note
2637727
CVSS
6.3

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-24739] Missing authorization check in SAP Bank Account Management

 

Related note
3417627
CVSS
8.8

Affected system type
Java
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application)

 

Related note
3421659
CVSS
7.4

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22132] Code Injection vulnerability in SAP IDES Systems

 

Related note
3424610
CVSS
7.4

Affected system type
SAP Cloud Connector
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-25642] Improper Certificate Validation in SAP Cloud Connector

 

Related note
3360827
CVSS
5.3

Affected system type
Kernel
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-24740] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (SAP Kernel)

 

Related note
3237638
CVSS
4.3

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-25643] Missing authorization check in SAP Fiori app ("My Overtime Requests")

 

Related note
3404025
CVSS
5.4

Affected system type
SAP Enable Now
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22129] Cross-Site Scripting (XSS) vulnerability in SAP Companion

 

Related note
3420923
CVSS
9.1

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22131] Code Injection vulnerability in SAP ABA (Application Basis)

 

Related note
2897391
CVSS
4.3

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/01

Description
[CVE-2024-24741] Missing Authorization check in SAP Master Data Governance Material

 

Related note
3396109
CVSS
4.7

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22128] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Business Client for HTML

 

Related note
3392626
CVSS
4.1

Affected system type
Kernel / Web Dispatcher
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-22124] Information Disclosure vulnerability in SAP NetWeaver Internet Communication Manager

 

Related note
3407617
CVSS
7.3

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21735] Improper Authorization check in SAP LT Replication Server

 

Related note
3386378
CVSS
7.4

Affected system type
SAP GUI / Frontend
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-22125] Information Disclosure vulnerability in Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge)

 

Related note
3389917
CVSS
7.5

Affected system type
Kernel
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2023-44487] Denial of service (DOS) in SAP Web Dispatcher, SAP NetWeaver Application server ABAP, and ABAP Platform

 

Related note
3412456
CVSS
9.1

Affected system type
BTP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA

 

Related note
3190894
CVSS
3.7

Affected system type
SAP Marketing
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21734] URL Redirection vulnerability in SAP Marketing (Contacts App)

 

Related note
3413475
CVSS
9.1

Affected system type
SAP Edge Integration
Patchday
2024-01
Released on
2024/01/09

Description
[Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell

 

Related note
3387737
CVSS
4.1

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21738] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform

 

Related note
3411869
CVSS
8.4

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21737] Code Injection vulnerability in SAP Application Interface Framework (File Adapter)

 

Related note
3260667
CVSS
6.4

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21736] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)

 

Related note
3406786
CVSS
4.3

Affected system type
SAP UI5
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-49584] Client-Side Desynchronization vulnerability in SAP Fiori Launchpad

 

Related note
3159329
CVSS
5.3

Affected system type
ABAP
Patchday
2023-12
Released on
2023/12/12

Description
Denial of service (DoS) vulnerability in JSZip library bundled within SAPUI5

 

Related note
3362463
CVSS
3.5

Affected system type
SAP Cloud Connector
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-49578] Denial of service (DOS) in SAP Cloud Connector

 

Related note
3395306
CVSS
6.4

Affected system type
ABAP
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-49587] Command Injection vulnerability in SAP Solution Manager

 

Related note
3411067
CVSS
9.1

Affected system type
BTP
Patchday
2023-12
Released on
2023/12/12

Description
[Multiple CVEs] Escalation of Privileges in SAP Business Technology Platform (BTP) Security Services Integration Libraries

 

Related note
3382353
CVSS
7.5

Affected system type
BI/BO platform
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-42478] Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform

 

Related note
3363690
CVSS
3.5

Affected system type
ABAP
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-49058] Directory Traversal vulnerability in SAP Master Data Governance

 

Related note
3217087
CVSS
6.1

Affected system type
ABAP
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-49577] Cross-Site Scripting (XSS) vulnerability in the SAP HCM (SMART PAYE solution)

 

Related note
3399691
CVSS
9.1

Affected system type
ABAP
Patchday
2023-12
Released on
2023/12/12

Description
Update 1 to 3350297 - [CVE-2023-36922] OS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)

 

Related note
3369353
CVSS
6.8

Affected system type
BI/BO platform
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-42476] Cross Site Scripting vulnerability in SAP BusinessObjects Web Intelligence

 

Related note
3406244
CVSS
7.1

Affected system type
Android SDK
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-6542] Missing Authorization Check in SAP EMARSYS SDK ANDROID

 

Related note
3383321
CVSS
6.1

Affected system type
Java
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-42479] Cross-Site Scripting (XSS) vulnerability in SAP Biller Direct

 

Related note
3385711
CVSS
7.3

Affected system type
SAP GUI / Frontend
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-49580] Information disclosure vulnerability in SAP GUI for WIndows and SAP GUI for Java

 

Related note
3394567
CVSS
8.1

Affected system type
SAP Commerce
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-42481] Improper Access Control vulnerability in SAP Commerce Cloud

 

Related note
3392547
CVSS
4.1

Affected system type
ABAP
Patchday
2023-12
Released on
2023/12/12

Description
[CVE-2023-49581] SQL Injection vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform

 

Related note
3355658
CVSS
9.6

Affected system type
SAP Business One
Patchday
2023-11
Released on
2023/11/14

Description
[CVE-2023-31403] Improper Access Control vulnerability in SAP Business One product installation

 

Related note
3366410
CVSS
5.3

Affected system type
Java
Patchday
2023-11
Released on
2023/11/14

Description
[CVE-2023-42480] Information Disclosure in NetWeaver AS Java Logon

 

Related note
3362849
CVSS
5.3

Affected system type
Kernel
Patchday
2023-11
Released on
2023/11/14

Description
[CVE-2023-41366] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform

 

Related note
3338380
CVSS
4.3

Affected system type
SAP Business One
Patchday
2023-10
Released on
2023/10/10

Description
[CVE-2023-41365] Information Disclosure vulnerability in SAP Business One (B1i)

 

Related note
3357154
CVSS
6.5

Affected system type
SAP PowerDesigner
Patchday
2023-10
Released on
2023/10/10

Description
[CVE-2023-40310] Missing XML Validation vulnerability in SAP PowerDesigner Client (BPMN2 import)

 

Related note
3222121
CVSS
4.3

Affected system type
ABAP
Patchday
2023-10
Released on
2023/10/10

Description
[CVE-2023-42475] Information Disclosure Vulnerability in Statutory Reporting

 

Related note
3333426
CVSS
6.5

Affected system type
Java
Patchday
2023-10
Released on
2023/10/26

Description
[CVE-2023-42477] Server-Side Request Forgery in SAP NetWeaver AS Java (GRMG Heartbeat application)

 

Related note
3372991
CVSS
6.8

Affected system type
BI/BO platform
Patchday
2023-10
Released on
2023/10/10

Description
[CVE-2023-42474] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Web Intelligence

 

Related note
3371873
CVSS
5.3

Affected system type
Java
Patchday
2023-10
Released on
2023/10/10

Description
Update 1 to Security Note 3324732: [CVE-2023-31405] Log Injection vulnerability in SAP NetWeaver AS for Java (Log Viewer)

 

Related note
3352453
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-37489] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Version Management System)

 

Related note
3323163
CVSS
5.5

Affected system type
ABAP
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40624] Code Injection vulnerability in SAP NetWeaver AS ABAP (applications based on Unified Rendering)

 

Related note
3326361
CVSS
5.4

Affected system type
ABAP
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40625] Missing Authorization check in Manage Purchase Contracts App

 

Related note
3370490
CVSS
8.7

Affected system type
BI/BO platform
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-42472] Insufficient File type validation in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)

 

Related note
3349805
CVSS
5.7

Affected system type
Java
Patchday
2023-09
Released on
2023/09/12

Description
Denial of service (DOS) vulnerability due to the usage of vulnerable version of Commons File Upload in SAP Quotation Management Insurance (FS-QUO)

 

Related note
3320355
CVSS
9.9

Affected system type
SAP BI
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40622] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management)

 

Related note
3357163
CVSS
6.3

Affected system type
PowerDesigner
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40621] Code Injection vulnerability in SAP PowerDesigner Client

 

Related note
3317702
CVSS
6.2

Affected system type
BI/BO platform
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40623] Arbitrary File Delete via Directory Junction in SAP BusinessObjects Suite(installer)

 

Related note
3327896
CVSS
7.5

Affected system type
Kernel
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40308] Memory Corruption vulnerability in SAP CommonCryptoLib

 

Related note
3355675
CVSS
2.7

Affected system type
ABAP
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-41368] Insecure Direct Object Reference (IDOR) vulnerability in SAP S/4HANA (Manage checkbook apps)

 

Related note
3340576
CVSS
9.8

Affected system type
Kernel, HANA...
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40309] Missing Authorization check in SAP CommonCryptoLib

 

Related note
3369680
CVSS
3.5

Affected system type
ABAP
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-41369] External Entity Loop vulnerability in SAP S/4HANA (Create Single Payment application)

 

Related note
3348142
CVSS
5.3

Affected system type
Java
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-41367] Missing Authentication check in SAP NetWeaver (Guided Procedures)

 

Related note
3312047
CVSS
7.5

Affected system type
BI/BO platform
Patchday
2023-08
Released on
2023/08/08

Description
Denial of Service (DoS) vulnerability due to the usage of vulnerable version of Commons FileUpload in SAP BusinessObjects Business Intelligence Platform (CMC)

 

Related note
3341934
CVSS
5.9

Affected system type
SAP Commerce Cloud
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37486] Information Disclosure vulnerability in SAP Commerce (OCC API)

 

Related note
3341460
CVSS
9.8

Affected system type
SAP PowerDesigner
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37483] Multiple Vulnerabilities in SAP PowerDesigner

 

Related note
3337797
CVSS
7.1

Affected system type
SAP Business One
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-33993] SQL Injection vulnerability in SAP Business One (B1i Layer)

 

Related note
3341599
CVSS
7.8

Affected system type
SAP PowerDesigner
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-36923] Code Injection vulnerability in SAP PowerDesigner

 

Related note
3312586
CVSS
4.4

Affected system type
BI/BO platform
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-39440] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform

 

Related note
3344295
CVSS
7.5

Affected system type
Kernel
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37491] Improper Authorization check vulnerability in SAP Message Server

 

Related note
3350494
CVSS
6.1

Affected system type
Java
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37488] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Process Integration

 

Related note
3317710
CVSS
7.6

Affected system type
BI/BO platform
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37490] Binary hijack in SAP BusinessObjects Business Intelligence Suite (installer)

 

Related note
2032723
CVSS
6.3

Affected system type
ABAP
Patchday
2023-08
Released on
2014/11/11

Description
Switchable authorization checks for RFC in SRM

 

Related note
3350297
CVSS
9.1

Affected system type
ABAP
Patchday
2023-08
Released on
2023/07/11

Description
[CVE-2023-36922] OS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)

 

Related note
2067220
CVSS
5.8

Affected system type
ABAP
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-39436] Information Disclosure in SAP Supplier Relationship Management

 

Related note
3333616
CVSS
5.3

Affected system type
SAP Business One
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37487] Security Misconfiguration vulnerability in SAP Business One (Service Layer)

 

Related note
3346500
CVSS
8.8

Affected system type
SAP Commerce Cloud
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-39439] Improper authentication in SAP Commerce Cloud

 

Related note
3156972
CVSS
6.1

Affected system type
ABAP
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-40306] URL Redirection vulnerability in SAP S/4HANA (Manage Catalog Items and Cross-Catalog search)

 

Related note
3348000
CVSS
4.9

Affected system type
ABAP
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37492] Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3149794
CVSS
6.1

Affected system type
SAP UI5
Patchday
2023-08
Released on
2023/08/08

Description
Cross-Site Scripting (XSS) vulnerabilities in jQuery-UI library bundled with SAPUI5

 

Related note
3358328
CVSS
3.7

Affected system type
SAP Host Agent
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-36926] Information disclosure vulnerability in SAP Host Agent

 

Related note
3358300
CVSS
7.6

Affected system type
SAP Business One
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-39437] Cross-Site Scripting (XSS) vulnerability in SAP Business One

 

Related note
3331376
CVSS
8.7

Affected system type
ABAP
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-33989] Directory Traversal vulnerability in SAP NetWeaver (BI CONT ADD ON)

 

Related note
3340735
CVSS
7.7

Affected system type
Kernel
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-35871] Memory Corruption vulnerability in SAP Web Dispatcher

 

Related note
3233899
CVSS
8.6

Affected system type
Kernel
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-33987] Request smuggling and request concatenation vulnerability in SAP Web Dispatcher

 

Related note
3343564
CVSS
6.5

Affected system type
Java
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-35872] Missing Authentication check in SAP NetWeaver Process Integration (Message Display Tool)

 

Related note
3343547
CVSS
6.5

Affected system type
Java
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-35873] Missing Authentication check in SAP NetWeaver Process Integration (Runtime Workbench)

 

Related note
3341211
CVSS
6.3

Affected system type
ABAP
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-35870] Improper Access Control in SAP S/4HANA (Manage Journal Entry Template)

 

Related note
3326769
CVSS
6.1

Affected system type
SAP Enable Now
Patchday
2023-07
Released on
2023/07/11

Description
[Multiple CVEs] Multiple Vulnerabilities in SAP Enable Now

 

Related note
3352058
CVSS
7.2

Affected system type
Java
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-36925] Unauthenticated blind SSRF in SAP Solution Manager (Diagnostics agent)

 

Related note
3331029
CVSS
7.8

Affected system type
Sybase platform
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-33990] Denial of service (DOS) vulnerability in SAP SQL Anywhere

 

Related note
3088078
CVSS
4.5

Affected system type
BI/BO platform
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-33992] Missing Authorization Check in SAP Business Warehouse and SAP BW/4HANA

 

Related note
3324732
CVSS
5.3

Affected system type
Java
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-31405] Log Injection vulnerability in SAP NetWeaver AS for Java (Log Viewer)

 

Related note
3318850
CVSS
6.0

Affected system type
Kernel
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-35874] Improper authentication vulnerability in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3351410
CVSS
4.9

Affected system type
ABAP
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-36924] Log Injection vulnerability in SAP ERP Defense Forces and Public Security

 

Related note
3320702
CVSS
5.9

Affected system type
BI/BO platform
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-36917] Password Change rate limit bypass in SAP BusinessObjects Business Intelligence Platform

 

Related note
3348145
CVSS
7.2

Affected system type
Java
Patchday
2023-07
Released on
2023/07/11

Description
[CVE-2023-36921] Header Injection in SAP Solution Manager (Diagnostic Agent)

 

Related note
3322800
CVSS
6.1

Affected system type
ABAP
Patchday
2023-06
Released on
2023/06/13

Description
Update 1 to security note 3315971 - [CVE-2023-30742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)

 

Related note
3325642
CVSS
2.7

Affected system type
ABAP
Patchday
2023-06
Released on
2023/06/13

Description
[CVE-2023-32114] Denial of Service in SAP NetWeaver (Change and Transport System)

 

Related note
3331627
CVSS
6.1

Affected system type
Java
Patchday
2023-06
Released on
2023/06/13

Description
[CVE-2023-33985] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (Enterprise Portal)

 

Related note
2826092
CVSS
6.1

Affected system type
ABAP
Patchday
2023-06
Released on
2023/06/13

Description
[CVE-2023-33986] Cross-Site Scripting (XSS) vulnerability in SAP CRM ABAP (Grantor Management)

 

Related note
3318657
CVSS
6.4

Affected system type
SAP...
Patchday
2023-06
Released on
2023/06/13

Description
[CVE-2023-33984] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (Design Time Repository)

 

Related note
3324285
CVSS
8.2

Affected system type
SAP UI5
Patchday
2023-06
Released on
2023/06/13

Description
[CVE-2023-33991] Stored Cross-Site Scripting vulnerability in SAP UI5 (Variant Management)

 

Related note
3319400
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-31406] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform

 

Related note
3320145
CVSS
7.5

Affected system type
SAP Commerce
Patchday
2023-05
Released on
2023/05/09

Description
Denial of service (DOS) in SAP Commerce

 

Related note
3326210
CVSS
7.1

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30743] Improper Neutralization of Input in SAPUI5

 

Related note
3323415
CVSS
8.2

Affected system type
SAP Integrated...
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-29080] Privilege escalation vulnerability in SAP IBP, add-in for Microsoft Excel

 

Related note
3300624
CVSS
7.5

Affected system type
SAP PowerDesigner
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-32111] Memory Corruption vulnerability in SAP PowerDesigner (Proxy)

 

Related note
1794761
CVSS
4.2

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/23

Description
[CVE-2023-32115] SQL Injection in Master Data Synchronization (MDS COMPARE TOOL)

 

Related note
3313484
CVSS
6.3

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30740] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform

 

Related note
3312892
CVSS
5.4

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-31407] Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation

 

Related note
3315979
CVSS
5.4

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-29188] Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI

 

Related note
3315971
CVSS
6.1

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)

 

Related note
3309935
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30741] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform

 

Related note
3302595
CVSS
3.7

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-28764] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform

 

Related note
3320467
CVSS
7.5

Affected system type
SAP GUI / Frontend
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-32113] Information Disclosure vulnerability in SAP GUI for Windows

 

Related note
2335198
CVSS
2.8

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-32112] Missing Authorization Check in Vendor Master Hierarchy

 

Related note
3038911
CVSS
5.0

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-31404] Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Service)

 

Related note
3328495
CVSS
9.8

Affected system type
Reprise License Manager
Patchday
2023-05
Released on
2023/05/09

Description
Multiple vulnerabilities associated with Reprise License Manager 14.2 component used with SAP 3D Visual Enterprise License Manager

 

Related note
3301942
CVSS
7.9

Affected system type
SAP Plant Connectivity
Patchday
2023-05
Released on
2023/05/23

Description
[CVE-2023-2827] Missing Authentication in SAP Plant Connectivity and Production Connector for SAP Digital Manufacturing

 

Related note
3317453
CVSS
8.2

Affected system type
Java
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30744] Improper access control during application start-up in SAP AS NetWeaver JAVA

 

Related note
3307833
CVSS
9.1

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-28762] Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Console)

 

Related note
3321309
CVSS
7.5

Affected system type
SAP Commerce
Patchday
2023-05
Released on
2023/05/09

Description
Information Disclosure vulnerability in SAP Commerce (Backoffice)

 

Related note
3114489
CVSS
3.7

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29112] Code Injection vulnerability in SAP Application Interface Framework (Message Monitoring)

 

Related note
3287784
CVSS
5.3

Affected system type
Java
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-24527] Improper Access Control in SAP NetWeaver AS Java for Deploy Service

 

Related note
3296378
CVSS
6.5

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-28763] - Denial of Service in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3311624
CVSS
6.7

Affected system type
SAP GUI / Frontend
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29187] DLL Hijacking vulnerability in SapSetup (Software Installation Program)

 

Related note
3316509
CVSS
4.7

Affected system type
SAP Commerce
Patchday
2023-04
Released on
2023/04/11

Description
Remote Code Execution vulnerability in SAP Commerce

 

Related note
3303060
CVSS
5.3

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29185] Denial of Service (DOS) in SAP NetWeaver AS for ABAP (Business Server Pages)

 

Related note
3275458
CVSS
6.1

Affected system type
Kernel
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-27499] Cross-Site Scripting (XSS) vulnerability in SAP GUI for HTML

 

Related note
3269352
CVSS
5.4

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29189] HTTP Verb Tampering vulnerability in SAP CRM (WebClient UI)

 

Related note
3115598
CVSS
4.4

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29109] Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard)

 

Related note
3289994
CVSS
6.5

Affected system type
Java
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-28761] Missing Authentication check in SAP NetWeaver Enterprise Portal

 

Related note
3305369
CVSS
10.0

Affected system type
Java
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-27497] Multiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge and EventLogServiceCollector)

 

Related note
3298961
CVSS
9.8

Affected system type
BI/BO platform
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-28765] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management )

 

Related note
3301457
CVSS
4.3

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-1903] Missing Authorization check in SAP HCM Fiori App My Forms (Fiori 2.0)

 

Related note
3312733
CVSS
6.8

Affected system type
Java
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-26458] Information Disclosure vulnerability in SAP Landscape Management

 

Related note
3113349
CVSS
3.7

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29110] Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard)

 

Related note
3305907
CVSS
8.7

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29186] Directory Traversal vulnerability in SAP NetWeaver ( BI CONT ADD ON)

 

Related note
3309056
CVSS
6.0

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-27897] Code Injection vulnerability in SAP CRM

 

Related note
3315312
CVSS
5.0

Affected system type
Kernel
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29108] IP filter vulnerability in ABAP Platform and SAP Web Dispatcher

 

Related note
3117978
CVSS
3.1

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29111] Information Disclosure vulnerability in SAP Application Interface Framework (ODATA service)

 

Related note
3274920
CVSS
6.1

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-0021] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver

 

Related note
3288394
CVSS
5.3

Affected system type
Java
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-24526] Improper Access Control in SAP NetWeaver AS Java (Classload Service)

 

Related note
3289844
CVSS
6.8

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-25615] SQL Injection vulnerability in SAP ABAP Platform

 

Related note
3287120
CVSS
6.5

Affected system type
BI/BO platform
Patchday
2023-03
Released on
2023/03/14

Description
[Multiple CVEs] Multiple vulnerabilities in the SAP BusinessObjects Business Intelligence platform

 

Related note
3294954
CVSS
8.7

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27501] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3296346
CVSS
7.4

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-26459] Multiple vulnerabilities in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3252433
CVSS
9.9

Affected system type
Java
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-23857] Improper Access Control in SAP NetWeaver AS for Java

 

Related note
3245526
CVSS
9.9

Affected system type
BI/BO platform
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-25616] Code Injection vulnerability in SAP Business Objects Business Intelligence Platform (CMC)

 

Related note
3283438
CVSS
9.0

Affected system type
BI/BO platform
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-25617] OS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform (Adaptive Job Server)

 

Related note
3284550
CVSS
6.8

Affected system type
Java
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-26461] XML External Entity (XXE) vulnerability in SAP NetWeaver (SAP Enterprise Portal)

 

Related note
3296476
CVSS
8.8

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27893] Arbitrary Code Execution in SAP Solution Manager and ABAP managed systems (ST-PI)

 

Related note
3302710
CVSS
6.1

Affected system type
SAP Authenticator for Android
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27895] Information Disclosure vulnerability in SAP Authenticator for Android

 

Related note
3302162
CVSS
9.6

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27500] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3294595
CVSS
9.6

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27269] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3275727
CVSS
7.2

Affected system type
SAP Host Agent
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27498] Memory Corruption vulnerability in SAPOSCOL

 

Related note
3296328
CVSS
6.5

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27270] Denial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3281484
CVSS
6.1

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-26457] Cross-Site Scripting (XSS) vulnerability in SAP Content Server

 

Related note
3288096
CVSS
5.3

Affected system type
Java
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-26460] Improper Access Control in SAP NetWeaver AS Java (Cache Management Service)

 

Related note
3288480
CVSS
5.3

Affected system type
Java
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27268] Improper Access Control in SAP NetWeaver AS Java (Object Analyzing Service)

 

Related note
3266751
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-23852] Cross-Site Scripting (XSS) vulnerability in SAP Solution Manager 7.2

 

Related note
3263863
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-23856] Cross-Site Scripting (XSS) vulnerability in Web Intelligence Interface

 

Related note
3275841
CVSS
5.4

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-23851] Unrestricted File Upload in SAP Business Planning and Consolidation

 

Related note
2985905
CVSS
6.5

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24524] Missing Authorization check in SAP S/4 HANA Map Treasury Correspondence Format Data

 

Related note
3290901
CVSS
6.5

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24528] Missing Authorization Check in SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests)

 

Related note
3263135
CVSS
8.5

Affected system type
BI/BO platform
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-0020] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence platform

 

Related note
3271227
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-23853] URL Redirection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
3265846
CVSS
6.5

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-0024] Cross Site Scripting in SAP Solution Manager (BSP Application)

 

Related note
3274585
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-25614] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Framework)

 

Related note
3256787
CVSS
8.4

Affected system type
BI/BO platform
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24530] Unrestricted Upload of File in SAP BusinessObjects Business Intelligence Platform (CMC)

 

Related note
3281724
CVSS
6.5

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-0019] Missing Authorization check in SAP GRC (Process Control)

 

Related note
3287291
CVSS
3.8

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-23854] Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3285757
CVSS
8.8

Affected system type
SAP Host Agent
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24523] Privilege Escalation vulnerability in SAP Host Agent (Start Service)

 

Related note
3268959
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[Multiple CVEs] Multiple vulnerabilities in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3269118
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24522] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Framework)

 

Related note
3269151
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24521] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Framework)

 

Related note
3282663
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24529] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (Business Server Pages application)

 

Related note
2788178
CVSS
4.3

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24525] Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI

 

Related note
3270509
CVSS
6.5

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-23855] URL Redirection vulnerability in SAP Solution Manager

 

Related note
3293786
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-23858] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3267442
CVSS
6.5

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-0025] Cross Site Scripting in SAP Solution Manager (BSP Application)

 

Related note
3251447
CVSS
4.6

Affected system type
BI/BO platform
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0015] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence (Web Intelligence)

 

Related note
3283283
CVSS
6.1

Affected system type
ABAP
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0013] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3276120
CVSS
6.4

Affected system type
SAP Host Agent
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0012] Local Privilege Escalation in SAP Host Agent (Windows)

 

Related note
3150704
CVSS
4.5

Affected system type
ABAP
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0023] Information Disclosure in SAP Bank Account Management (Manage Banks)

 

Related note
3266006
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0018] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)

 

Related note
3089413
CVSS
9.0

Affected system type
Kernel / ABAP
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0014] Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3268093
CVSS
9.4

Affected system type
Java
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0017] Improper access control in SAP NetWeaver AS for Java

 

Related note
3275391
CVSS
9.9

Affected system type
SAP Business Planning...
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0016] SQL Injection vulnerability in SAP Business Planning and Consolidation MS

 

Related note
3262810
CVSS
9.9

Affected system type
BI/BO platform
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0022] Code Injection vulnerability in SAP BusinessObjects Business Intelligence platform (Analysis edition for OLAP)

 

Related note
3262544
CVSS
6.1

Affected system type
Java
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41262] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for Java (Http Provider Service)

 

Related note
3270399
CVSS
4.3

Affected system type
Java
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41273] URL Redirection vulnerability in SAP Sourcing and SAP Contract Lifecycle Management

 

Related note
3239475
CVSS
9.9

Affected system type
BI/BO platform
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41267] Server-Side Request Forgery vulnerability in SAP BusinessObjects Business Intelligence Platform

 

Related note
3267780
CVSS
9.4

Affected system type
Java
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41271] Improper access control in SAP NetWeaver AS Java (Messaging System)

 

Related note
3249648
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41263] Missing authentication check vulnerability in SAP Business Objects Business Intelligence Platform (Web intelligence)

 

Related note
3271523
CVSS
9.8

Affected system type
SAP Commerce
Patchday
2022-12
Released on
2022/12/13

Description
Remote Code Execution vulnerability associated with Apache Commons Text in SAP Commerce

 

Related note
3271091
CVSS
8.5

Affected system type
ABAP
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41268] Privilege escalation vulnerability in SAP Business Planning and Consolidation

 

Related note
3273480
CVSS
9.9

Affected system type
Java
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41272] Improper access control in SAP NetWeaver AS Java (User Defined Search)

 

Related note
3265173
CVSS
6.0

Affected system type
Java
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41261] Improper Access Control in SAP Solution Manager (Diagnostic Agent)

 

Related note
3268172
CVSS
8.8

Affected system type
ABAP
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41264] Code Injection vulnerability in SAP BASIS

 

Related note
3258950
CVSS
6.1

Affected system type
ABAP
Patchday
2022-12
Released on
2022/12/13

Description
Update 1 to Security Note 2872782 - [CVE-2020-6215] URL Redirection vulnerability in SAP NetWeaver AS ABAP (BSP Test Application)

 

Related note
3248255
CVSS
8.0

Affected system type
SAP Commerce
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41266] Cross-Site Scripting (XSS) vulnerability in SAP Commerce

 

Related note
3271313
CVSS
6.1

Affected system type
ABAP
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41275] Offener Redirect in SAP Solutions Manager (Enterprise Search)

 

Related note
3266846
CVSS
6.5

Affected system type
SAP Disclosure Management
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41274] Missing Authorization Checks in SAP Disclosure Management

 

Related note
3218159
CVSS
6.1

Affected system type
SAP UI5 SAP Fiori
Patchday
2022-11
Released on
2022/11/08

Description
Insufficient Session Expiration in Central Fiori Launchpad

 

Related note
3229987
CVSS
6.5

Affected system type
Sybase platform
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41259] Denial of service (DOS) in SAP SQL Anywhere

 

Related note
3260708
CVSS
6.5

Affected system type
SAP Financial Consolidation
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41258] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation

 

Related note
3238042
CVSS
6.1

Affected system type
Java
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41207] URL Redirection vulnerability in SAP Biller Direct

 

Related note
3251202
CVSS
4.7

Affected system type
ABAP
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform

 

Related note
3243924
CVSS
9.9

Affected system type
BI/BO platform
Exploit available
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41203] Insecure Deserialization of Untrusted Data in SAP BusinessObjects Business Intelligence Platform (Central Management Console and BI Launchpad)

 

Related note
3263436
CVSS
7.0

Affected system type
SAP 3D Visual Enterprise
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41211] Arbitrary Code Execution vulnerability in SAP 3D Visual Enterprise Author and SAP 3D Visual Enterprise Viewer

 

Related note
3237251
CVSS
5.5

Affected system type
SAP GUI / Frontend
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41205] Code injection vulnerability in SAP GUI for Windows

 

Related note
3256571
CVSS
8.7

Affected system type
ABAP
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41214] Multiple vulnerabilities in SAP NetWeaver Application Server ABAP and ABAP Platform

 

Related note
3249990
CVSS
7.5

Affected system type
ABAP, Java
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2021-20223] Multiple Vulnerabilities in SQlite bundled with SAPUI5

 

Related note
3229425
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-41206] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform / Analysis for OLAP

 

Related note
3248970
CVSS
4.9

Affected system type
SAP Customer Data Cloud
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-41209] Information Disclosure Vulnerability in SAP Customer Data Cloud (Gigya)

 

Related note
3248384
CVSS
4.9

Affected system type
SAP Customer Data Cloud
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-41210] Information Disclosure Vulnerability in SAP Customer Data Cloud (Gigya)

 

Related note
3242933
CVSS
9.9

Affected system type
Java
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-39802] File path traversal vulnerability in SAP Manufacturing Execution

 

Related note
3232021
CVSS
8.1

Affected system type
Sybase platform
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-35299] Buffer Overflow in SAP SQL Anywhere and SAP IQ

 

Related note
3245929
CVSS
7.0

Affected system type
SAP 3D Visual Enterprise
Patchday
2022-10
Released on
2022/10/11

Description
[Multiple CVEs] Multiple vulnerabilities in SAP 3D Visual Enterprise Author

 

Related note
3233226
CVSS
6.8

Affected system type
BI/BO platform
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-35296] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Version Management System)

 

Related note
3229132
CVSS
8.2

Affected system type
BI/BO platform
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-39013] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Program Objects)

 

Related note
2495712
CVSS
6.5

Affected system type
ABAP
Patchday
2022-10
Released on
2022/10/11

Description
Missing authorization check in SAP Automotive Solutions

 

Related note
3234755
CVSS
4.3

Affected system type
ABAP
Patchday
2022-10
Released on
2022/10/11

Description
Information Disclosure vulnerability in Master Data Governance

 

Related note
3211161
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-39800] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI LaunchPad)

 

Related note
3245928
CVSS
7.0

Affected system type
SAP 3D Visual Enterprise
Patchday
2022-10
Released on
2022/10/11

Description
[Multiple CVEs] Multiple vulnerabilities in SAP 3D Visual Enterprise Viewer

 

Related note
3239293
CVSS
7.7

Affected system type
BI/BO platform
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-39015] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform(AdminTools/ Query Builder)

 

Related note
3049899
CVSS
6.5

Affected system type
SAP Enable Now
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-35297] Stored Cross-Site Scripting (XSS) vulnerability in SAP Enable Now

 

Related note
3167342
CVSS
4.8

Affected system type
BI/BO platform
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-35226] Cross-Site Scripting (XSS) vulnerability in Data Services Management Console

 

Related note
3202523
CVSS
6.1

Affected system type
SAP Commerce
Patchday
2022-10
Released on
2022/10/11

Description
Cross-Site Scripting (XSS) vulnerability in SAP Commerce

 

Related note
3126968
CVSS
4.3

Affected system type
ABAP
Patchday
2022-09
Released on
2022/09/13

Description
Information Disclosure vulnerability in SAP CRM WebClient

 

Related note
3218177
CVSS
5.4

Affected system type
ABAP
Patchday
2022-09
Released on
2022/09/13

Description
[CVE-2022-35294] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP

 

Related note
2634023
CVSS
6.3

Affected system type
ABAP
Patchday
2022-09
Released on
2022/09/13

Description
Missing authorization check in Consumption of CDS Views (or) OData Services in QM-QN

 

Related note
3217303
CVSS
7.7

Affected system type
BI/BO platform
Patchday
2022-09
Released on
2022/09/13

Description
[CVE-2022-39014] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (CMC)

 

Related note
3219164
CVSS
6.1

Affected system type
Java
Patchday
2022-09
Released on
2022/09/13

Description
[CVE-2022-35298] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC)

 

Related note
3237075
CVSS
7.1

Affected system type
ABAP
Patchday
2022-09
Released on
2022/09/13

Description
[CVE-2022-39801] Insufficient Firefighter Session Expiration in SAP GRC Access Control Emergency Access Management

 

Related note
3229820
CVSS
6.1

Affected system type
ABAP
Patchday
2022-09
Released on
2022/09/13

Description
[CVE-2022-39799] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad)

 

Related note
3223392
CVSS
7.8

Affected system type
SAP Business One
Patchday
2022-09
Released on
2022/09/13

Description
[CVE-2022-35292] Windows Unquoted Service Path issue in SAP Business One

 

Related note
3159736
CVSS
6.7

Affected system type
SAP Host Agent
Patchday
2022-09
Released on
2022/09/13

Description
[CVE-2022-35295] Privilege Escalation Vulnerability in SAPOSCOL on Unix

 

Related note
3198137
CVSS
4.7

Affected system type
ABAP
Patchday
2022-09
Released on
2022/09/13

Description
Update 1 to Security Note 3165333 - [CVE-2022-28215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform

 

Related note
3213507
CVSS
5.2

Affected system type
BI/BO platform
Patchday
2022-08
Released on
2022/08/09

Description
[CVE-2022-31596] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Monitoring DB)

 

Related note
3216653
CVSS
5.3

Affected system type
SAP Authenticator for Android
Patchday
2022-08
Released on
2022/08/09

Description
[CVE-2022-35290] Information Disclosure in SAP Authenticator for Android

 

Related note
3210823
CVSS
8.2

Affected system type
BI/BO platform
Patchday
2022-08
Released on
2022/08/09

Description
[CVE-2022-32245] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Open Document)

 

Related note
3213141
CVSS
7.3

Affected system type
SAP Landscape...
Patchday
2022-08
Released on
2022/07/26

Description
Information Disclosure in SAP Landscape Management

 

Related note
3210566
CVSS
4.2

Affected system type
SAP Enable Now
Patchday
2022-08
Released on
2022/08/09

Description
[CVE-2022-35293] Missing authorization check in SAP Enable Now Manager

 

Related note
2522794
CVSS
6.3

Affected system type
ABAP
Patchday
2022-08
Released on
2022/08/09

Description
Missing Authorization check in Portugal Digital Signature

 

Related note
3213524
CVSS
5.2

Affected system type
BI/BO platform
Patchday
2022-08
Released on
2022/08/09

Description
[CVE-2022-32244] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Commentary DB)

 

Related note
3156484
CVSS
6.5

Affected system type
SAP GUI / Frontend
Patchday
2022-08
Released on
2022/08/09

Description
Information Disclosure vulnerability in SAP Business Client

 

Related note
3167430
CVSS
5.6

Affected system type
BI/BO platform
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-31591] Privilege Escalation vulnerability in SAP BusinessObjects (BW Publisher Service)

 

Related note
3196280
CVSS
4.3

Affected system type
ABAP
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-31592] Missing Authorization check in EA-DFPS

 

Related note
3207902
CVSS
6.1

Affected system type
Java
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35172] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3213279
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-31598] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects

 

Related note
3213826
CVSS
5.4

Affected system type
ABAP
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-31597] Missing Authorization check in SAP S/4HANA(business partner extension for Spain/Slovakia)

 

Related note
3209557
CVSS
6.1

Affected system type
Java
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-32247] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3208880
CVSS
6.1

Affected system type
Java
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35225] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3220746
CVSS
3.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35171] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3150454
CVSS
4.9

Affected system type
ABAP
Patchday
2022-07
Released on
2022/07/12

Description
Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform

 

Related note
3210779
CVSS
6.1

Affected system type
Java
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35224] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Portal

 

Related note
3157613
CVSS
7.5

Affected system type
SAP Business One
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-28771] Missing Authentication check in SAP Business One (License service API)

 

Related note
3221288
CVSS
8.3

Affected system type
BI/BO platform
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35228] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)

 

Related note
3211760
CVSS
6.1

Affected system type
Java
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35227] Cross-Site Scripting (XSS) vulnerability in SAP NW EP WPC

 

Related note
3169239
CVSS
6.5

Affected system type
BI/BO platform
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-29619] Information Disclosure to user Administrator in SAP BusinessObjects Business Intelligence Platform 4.x

 

Related note
3211203
CVSS
4.3

Affected system type
SAP Business One
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35168] Denial of Service vulnerability in SAP Business One

 

Related note
3216161
CVSS
4.3

Affected system type
ABAP
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-32248] Missing Input Validation in Manage Checkbooks component of SAP S/4HANA

 

Related note
3194361
CVSS
6.0

Affected system type
BI/BO platform
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35169] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (LCM)

 

Related note
3208819
CVSS
6.1

Affected system type
Java
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35170] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3203079
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-32246] SQL Injection vulnerability in SAP BusinessObjects Business Intelligence Platform (Visual Difference Application)

 

Related note
3150463
CVSS
4.9

Affected system type
ABAP
Patchday
2022-07
Released on
2022/07/12

Description
Information Disclosure vulnerability in ABAP Platform

 

Related note
3191012
CVSS
7.4

Affected system type
SAP Business One
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-31593] Code Injection vulnerability in SAP Business One

 

Related note
3212997
CVSS
7.6

Affected system type
SAP Business One
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-32249] Information Disclosure vulnerability in SAP Business One

 

Related note
2726124
CVSS
6.3

Affected system type
ABAP
Patchday
2022-07
Released on
2022/06/28

Description
Missing Authorization Check in multiple components under SAP Automotive Solutions

 

Related note
3158619
CVSS
4.9

Affected system type
ABAP Java HANA platform
Patchday
2022-06
Released on
2022/06/14

Description
[CVE-2022-29614] Privilege Escalation in SAP startservice of SAP NetWeaver AS ABAP, AS Java, ABAP Platform and HANA Database

 

Related note
3147498
CVSS
8.2

Affected system type
Java
Patchday
2022-06
Released on
2022/06/14

Description
Improper Access Control check in SAP NetWeaver basicadmin and adminadapter services

 

Related note
3197005
CVSS
7.8

Affected system type
SAP PowerDesigner
Patchday
2022-06
Released on
2022/06/14

Description
[CVE-2022-31590] Potential privilege escalation in SAP PowerDesigner Proxy 16.7

 

Related note
3206271
CVSS
6.5

Affected system type
SAP 3D Visual Enterprise
Patchday
2022-06
Released on
2022/06/14

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3202846
CVSS
3.4

Affected system type
Java
Patchday
2022-06
Released on
2022/06/14

Description
[CVE-2022-29615] Multiple vulnerabilities associated with Apache log4j 1.x component in SAP NetWeaver Developer Studio (NWDS)

 

Related note
3197927
CVSS
6.1

Affected system type
SAP...
Patchday
2022-06
Released on
2022/06/14

Description
[CVE-2022-29618] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Development Infrastructure (Design Time Repository)

 

Related note
3158815
CVSS
5.0

Affected system type
SAP Financial Consolidation
Patchday
2022-06
Released on
2022/06/14

Description
[CVE-2022-31595] Privilege escalation vulnerability in SAP Financial Consolidation

 

Related note
3158375
CVSS
8.6

Affected system type
SAProuter
Patchday
2022-06
Released on
2022/06/14

Description
[CVE-2022-27668] Improper Access Control of SAProuter for SAP NetWeaver and ABAP Platform

 

Related note
3134161
CVSS
6.5

Affected system type
ABAP
Patchday
2022-06
Released on
2022/06/14

Description
Missing Authorization check in SAP ERP HCM

 

Related note
3194674
CVSS
5.0

Affected system type
ABAP SAP Host Agent
Patchday
2022-06
Released on
2022/06/14

Description
[CVE-2022-29612] Server-Side Request Forgery in SAP NetWeaver, ABAP Platform and SAP Host Agent

 

Related note
3190675
CVSS
3.7

Affected system type
UI5
Patchday
2022-06
Released on
2022/06/14

Description
Unsafe use of target blank in SAP Marketing Campaigns

 

Related note
3191812
CVSS
3.7

Affected system type
UI5
Patchday
2022-06
Released on
2022/06/14

Description
Cross-Site Scripting (XSS) vulnerability in SAP Marketing Campaigns App

 

Related note
3155571
CVSS
3.2

Affected system type
SAP Adaptive Server...
Patchday
2022-06
Released on
2022/06/14

Description
[CVE-2022-31594] Privilege escalation vulnerability in SAP Adaptive Server Enterprise (ASE)

 

Related note
3203065
CVSS
5.0

Affected system type
ABAP
Patchday
2022-06
Released on
2022/06/14

Description
[CVE-2022-31589] Segregation of Duty vulnerability in IL FI-AP File from SHAAM program.

 

Related note
3164677
CVSS
6.5

Affected system type
ABAP
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-29613] Information Disclosure vulnerability in SAP Employee Self Service(Fiori My Leave Request)

 

Related note
3145702
CVSS
5.3

Affected system type
SAP Host Agent Kernel
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-29616] Memory Corruption vulnerability in SAP Host Agent, SAP NetWeaver and ABAP Platform

 

Related note
3189409
CVSS
9.8

Affected system type
SAP Business One Cloud
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in in SAP Business One Cloud

 

Related note
2754555
CVSS
6.3

Affected system type
ABAP
Patchday
2022-05
Released on
2022/05/10

Description
Cross-Site Request Forgery (CSRF) vulnerability in F0673 Approve Bank Payments back-end

 

Related note
3146336
CVSS
5.4

Affected system type
ABAP
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-29610] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP

 

Related note
3143161
CVSS
4.3

Affected system type
ABAP
Patchday
2022-05
Released on
2022/05/10

Description
Missing Authorization check for UI5 flexibility key user functionality

 

Related note
3158188
CVSS
5.3

Affected system type
SAP Host Agent
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-28774] Information Disclosure vulnerability in SAP Host Agent logfile

 

Related note
3165801
CVSS
6.5

Affected system type
ABAP
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-29611] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
2756188
CVSS
6.3

Affected system type
UI5
Patchday
2022-05
Released on
2022/05/10

Description
Cross-Site Request Forgery (CSRF) vulnerability in F0673 Approve Bank Payments front-end

 

Related note
3145046
CVSS
8.3

Affected system type
Kernel
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-27656] Cross-Site Scripting (XSS) vulnerability in administration UI of SAP Webdispatcher and SAP Netweaver AS for ABAP and Java (ICM)

 

Related note
2998510
CVSS
7.8

Affected system type
BI/BO platform
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-28214] Central Management Server Information Disclosure in Business Intelligence Update

 

Related note
3171258
CVSS
9.8

Affected system type
SAP Commerce
Patchday
2022-04
Released on
2022/04/18

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Commerce

 

Related note
3158613
CVSS
9.1

Affected system type
Java
Patchday
2022-04
Released on
2022/04/12

Description
Update 1 to Security Note 3022622 - [CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence

 

Related note
3055044
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-28213] Missing XML Validation vulnerability in SAP BusinessObjects Business Intelligence Platform (dswsbobje - SOAP Web services)

 

Related note
3165333
CVSS
4.7

Affected system type
ABAP
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-28215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform

 

Related note
3137191
CVSS
6.8

Affected system type
BI/BO platform
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-22541] Information Disclosure vulnerability in SAP BusinessObjects Platform

 

Related note
3132633
CVSS
5.4

Affected system type
SAP GUI / Frontend
Patchday
2022-04
Released on
2022/04/12

Description
Information Disclosure vulnerability in SAP GUI for Windows

 

Related note
3145769
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-27667] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (CMC)

 

Related note
3189428
CVSS
9.8

Affected system type
SAP HANA Platform
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP HANA Extended Application Services

 

Related note
3111311
CVSS
7.5

Affected system type
Kernel
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-28772]Denial of service (DOS) in SAP Web Dispatcher and SAP Netweaver (Internet Communication Manager)

 

Related note
3163583
CVSS
6.1

Affected system type
Java
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-26105] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3187290
CVSS
9.8

Affected system type
SAP Customer Checkout
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Checkout

 

Related note
3150845
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-28216] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI Workspace)

 

Related note
3130497
CVSS
8.2

Affected system type
BI/BO platform
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-27671] CSRF token visible in one of the URL in SAP Business Intelligence Platform.

 

Related note
3143437
CVSS
6.5

Affected system type
SAP 3D Visual Enterprise
Patchday
2022-04
Released on
2022/04/12

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3155609
CVSS
7.0

Affected system type
SAP Commerce
Patchday
2022-04
Released on
2022/04/12

Description
Privilege escalation vulnerability in Apache Tomcat server component of SAP Commerce

 

Related note
3189635
CVSS
9.8

Affected system type
SAP Customer...
Patchday
2022-04
Released on
2022/04/14

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Profitability Analytics

 

Related note
3163703
CVSS
6.1

Affected system type
ABAP
Patchday
2022-04
Released on
2022/04/12

Description
Multiple Vulnerabilities in URI.js bundled with SAPUI5

 

Related note
3148377
CVSS
6.5

Affected system type
Java
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-28217] Missing XML Validation vulnerability in SAP NW EP WPC

 

Related note
3165856
CVSS
4.3

Affected system type
SAP Innovation Management
Patchday
2022-04
Released on
2022/03/28

Description
[CVE-2022-27658] Missing authorization check in SAP Innovation Management

 

Related note
3152442
CVSS
5.3

Affected system type
Java
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-27669] Missing Authentication check in XML Data Archiving Service

 

Related note
3170990
CVSS
9.8

Affected system type
Any
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-22965] Central Security Note for Remote Code Execution vulnerability associated with Spring Framework

 

Related note
3138299
CVSS
4.1

Affected system type
Adobe LiveCycle Designer
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2021-44832] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP NetWeaver ABAP Server and ABAP Platform (Adobe LiveCycle Designer 11.0)

 

Related note
3189429
CVSS
9.8

Affected system type
Java
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in PowerDesigner Web (up to including 16.7 SP05 PL01)

 

Related note
3159091
CVSS
2.7

Affected system type
SAP Solution Manager...
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-27657] Directory Traversal vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)

 

Related note
3148094
CVSS
6.5

Affected system type
Sybase
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-27670] Denial of service (DOS) in SQL Anywhere

 

Related note
3111293
CVSS
4.9

Affected system type
Kernel
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-28773] Denial of service (DOS) in SAP Web Dispatcher and SAP Netweaver (Internet Communication Manager)

 

Related note
3101986
CVSS
4.1

Affected system type
ABAP
Patchday
2022-04
Released on
2022/04/12

Description
Enable CSP support for OP1909 in SAP CRM WebClient UI

 

Related note
3126557
CVSS
6.1

Affected system type
ABAP
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-28770] Cross-Site Scripting (XSS) vulnerability in SAPUI5 (vbm library)

 

Related note
3145987
CVSS
9.3

Affected system type
SAP Solution Manager...
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-24396] Missing Authentication check in SAP Focused Run (Simple Diagnostics Agent 1.0)

 

Related note
3145997
CVSS
5.4

Affected system type
ABAP
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-26102] Missing authorization check in SAP NetWeaver Application Server for ABAP

 

Related note
3144941
CVSS
5.4

Affected system type
SAP Financial Consolidation
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-26104] Missing Authorization check in SAP Financial Consolidation

 

Related note
3103424
CVSS
5.0

Affected system type
BI/BO platform
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-24398] Information Disclosure vulnerability in SAP Business Objects Business Intelligence Platform

 

Related note
1753378
CVSS
5.3

Affected system type
Java
Patchday
2022-03
Released on
2013/08/13

Description
Directory traversal in Web Container

 

Related note
3104349
CVSS
3.3

Affected system type
ABAP
Patchday
2022-03
Released on
2022/03/22

Description
Missing authorization check in S/4HANA finance for advanced payment management

 

Related note
3147102
CVSS
5.3

Affected system type
SAP Solution Manager...
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-22547] Information Disclosure vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)

 

Related note
3111110
CVSS
4.8

Affected system type
SAPCAR
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-26100] Denial of service (DOS) in SAPCAR

 

Related note
3147283
CVSS
5.4

Affected system type
SAP Solution Manager...
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-24399] Cross-Site Scripting (XSS) vulnerability in SAP Focused Run (Real User Monitoring)

 

Related note
3132360
CVSS
3.7

Affected system type
Java
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-26103] Information Disclosure vulnerability in SAP NetWeaver(Real Time Messaging Framework)

 

Related note
3146260
CVSS
6.1

Affected system type
Java
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-24397] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3149805
CVSS
8.1

Affected system type
ABAP
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-26101] Cross-Site Scripting (XSS) vulnerability in SAP Fiori launchpad

 

Related note
3146261
CVSS
6.1

Affected system type
Java
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-24395] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3154684
CVSS
10.0

Affected system type
SAP Work Manager
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Work Manager

 

Related note
2531036
CVSS
6.3

Affected system type
ABAP
Patchday
2022-02
Released on
2019/04/09

Description
Switchable Authorization checks for RFC BCA_DIM_RESET_TRIGGER_TABLE in Loans (FI-CAX-FS)

 

Related note
3123396
CVSS
10.0

Affected system type
Kernel
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22536] Request smuggling and request concatenation in SAP NetWeaver, SAP Content Server and SAP Web Dispatcher

 

Related note
3128473
CVSS
4.9

Affected system type
ABAP
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22545] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform

 

Related note
3140587
CVSS
7.1

Affected system type
ABAP
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22540] SQL Injection vulnerability in SAP NetWeaver AS ABAP (Workplace Server)

 

Related note
3142773
CVSS
10.0

Affected system type
SAP Commerce
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Commerce

 

Related note
3126489
CVSS
6.5

Affected system type
ABAP
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22535] Missing Authorization check in SAP ERP HCM

 

Related note
3124994
CVSS
4.7

Affected system type
ABAP
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22534] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver

 

Related note
3130920
CVSS
10.0

Affected system type
SAP Data Intelligence
Patchday
2022-02
Released on
2022/01/18

Description
Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Data Intelligence 3 (on-premise)

 

Related note
3134684
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2022-02
Released on
2022/02/08

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3107196
CVSS
4.3

Affected system type
ABAP
Patchday
2022-02
Released on
2022/01/25

Description
Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver AS ABAP within Web Dynpro ABAP

 

Related note
3140564
CVSS
5.6

Affected system type
SAP Adaptive Server...
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22528] Information Disclosure in SAP Adaptive Server Enterprise

 

Related note
3126748
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22546] XSS vulnerability in SAP Business Objects Web Intelligence (BI Launchpad)

 

Related note
3123427
CVSS
8.1

Affected system type
Kernel
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22532] HTTP Request Smuggling in SAP NetWeaver Application Server Java

 

Related note
3140940
CVSS
9.1

Affected system type
Java
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22544] Missing segregation of duties in SAP Solution Manager Diagnostics Root Cause Analysis Tools

 

Related note
3116223
CVSS
3.7

Affected system type
Kernel
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22543] Denial of service (DOS) in SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel)

 

Related note
3139893
CVSS
10.0

Affected system type
None
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Dynamic Authorization Management

 

Related note
3142092
CVSS
6.5

Affected system type
ABAP
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22542] Information Disclosure vulnerability in SAP S/4HANA (Supplier Factsheet and Enterprise Search for Business Partner, Supplier and Customer)

 

Related note
3136988
CVSS
10.0

Affected system type
SAP IoT
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Reference Template for enabling ingestion and persistence of time series data in Azure

 

Related note
3133005
CVSS
5.3

Affected system type
Java
Patchday
2022-01
Released on
2021/12/28

Description
Update 2 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration

 

Related note
3101299
CVSS
6.6

Affected system type
SAP Business One
Patchday
2022-01
Released on
2021/12/14

Description
[CVE-2021-42066] Information Disclosure vulnerability in SAP Business One

 

Related note
3112928
CVSS
8.7

Affected system type
ABAP
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2022-22531] Multiple vulnerabilities in F0743 Create Single Payment application of SAP S/4HANA

 

Related note
3132058
CVSS
10.0

Affected system type
SAP IoT
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Cloud-to-Cloud Interoperability

 

Related note
3112710
CVSS
4.3

Affected system type
ABAP
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-42067] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
3106528
CVSS
6.5

Affected system type
SAP Business One
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44234] Information Disclosure vulnerability in SAP Business One

 

Related note
3132515
CVSS
10.0

Affected system type
SAP Edge Services 
Patchday
2022-01
Released on
2021/12/30

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services Cloud Edition

 

Related note
3124597
CVSS
6.1

Affected system type
SAP Enterprise Threat...
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2022-22529] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Threat Detection

 

Related note
3132177
CVSS
10.0

Affected system type
SAP Localization Hub
Patchday
2022-01
Released on
2021/12/22

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Localization Hub, digital compliance service for India

 

Related note
3134139
CVSS
10.0

Affected system type
SAP Enterprise...
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j2 component used in SAP Enterprise Continuous Testing by Tricentis

 

Related note
3136094
CVSS
10.0

Affected system type
SAP Digital...
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Digital Manufacturing Cloud for Edge Computing

 

Related note
3131691
CVSS
5.5

Affected system type
Adobe LiveCycle Designer
Patchday
2022-01
Released on
2021/12/30

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP NetWeaver ABAP Server and ABAP Platform (Adobe LiveCycle Designer 11.0)

 

Related note
3135581
CVSS
6.6

Affected system type
Java
Patchday
2022-01
Released on
2022/01/11

Description
Update 3 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration

 

Related note
3134531
CVSS
7.5

Affected system type
SAP HANA Platform
Patchday
2022-01
Released on
2021/12/24

Description
[CVE-2021-44228] Denial of Service vulnerability associated with Apache Log4j component used in XSA Cockpit

 

Related note
3131740
CVSS
9.8

Affected system type
SAP Business One
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Business One

 

Related note
3109577
CVSS
9.9

Affected system type
SAP Commerce
Patchday
2021-12
Released on
2021/12/14

Description
Code Execution vulnerability in SAP Commerce, localization for China

 

Related note
3132922
CVSS
10.0

Affected system type
SAP Edge Services 
Patchday
2021-12
Released on
2021/12/21

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Internet of Things Edge Platform

 

Related note
3114134
CVSS
8.8

Affected system type
SAP Commerce
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-42064] SQL Injection vulnerability in SAP Commerce

 

Related note
2661033
CVSS
6.3

Affected system type
ABAP
Patchday
2021-12
Released on
2021/11/23

Description
Missing Authorization check in RFC enabled function modules in SRM

 

Related note
3131824
CVSS
8.0

Affected system type
SAP Connected Health platform
Patchday
2021-12
Released on
2021/12/20

Description
[CVE-2021-44228] Log4j Vulnerability in Connected Health Platform 2.0 - Fhirserver

 

Related note
3119365
CVSS
9.9

Affected system type
ABAP
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-44231] Code Injection vulnerability in SAP ABAP Server & ABAP Platform (Translation Tools)

 

Related note
3124094
CVSS
7.7

Affected system type
ABAP
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-44232] Directory Traversal vulnerability in SAF-T Framework

 

Related note
3131047
CVSS
10.0

Affected system type
Any
Patchday
2021-12
Released on
2021/12/15

Description
[CVE-2021-44228] Central Security Note for Remote Code Execution vulnerability associated with Apache Log4j 2 component

 

Related note
3123196
CVSS
8.4

Affected system type
ABAP
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-44235] Code Injection vulnerability in utility class for SAP NetWeaver AS ABAP

 

Related note
3080816
CVSS
2.4

Affected system type
ABAP
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-44233] Missing Authorization check in GRC Access Control

 

Related note
3051005
CVSS
3.5

Affected system type
SAP UI5
Patchday
2021-12
Released on
2021/12/14

Description
Cross-Site Scripting (XSS) Vulnerability in SAP Fiori Launchpad

 

Related note
3131397
CVSS
10.0

Affected system type
SAP HANA Platform
Patchday
2021-12
Released on
2021/12/17

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit

 

Related note
3131258
CVSS
10.0

Affected system type
SAP HANA Platform
Patchday
2021-12
Released on
2021/12/16

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP HANA XSA

 

Related note
3133772
CVSS
10.0

Affected system type
SAP Customer Checkout
Patchday
2021-12
Released on
2021/12/22

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Customer Checkout

 

Related note
3130578
CVSS
10.0

Affected system type
SAP BTP Cloud Foundry runtime
Patchday
2021-12
Released on
2021/12/21

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Cloud Foundry

 

Related note
3132909
CVSS
10.0

Affected system type
SAP Edge Services 
Patchday
2021-12
Released on
2021/12/24

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services On Premise Edition

 

Related note
3132204
CVSS
3.1

Affected system type
Java
Patchday
2021-12
Released on
2021/12/16

Description
Update 1 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration

 

Related note
3103677
CVSS
4.1

Affected system type
BI/BO platform
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-42061] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform (Web Intelligence)

 

Related note
3132964
CVSS
10.0

Affected system type
SAP Enable Now
Patchday
2021-12
Released on
2021/12/23

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Enable Now Manager

 

Related note
3132198
CVSS
9.8

Affected system type
SAP Landscape...
Patchday
2021-12
Released on
2021/12/20

Description
[CVE-2019-17571] Code Injection vulnerability in SAP Landscape Management

 

Related note
3132822
CVSS
9.0

Affected system type
SAP HANA Platform
Patchday
2021-12
Released on
2021/12/21

Description
Update 1 to Security Note 3131397 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit

 

Related note
3132744
CVSS
10.0

Affected system type
SAP BTP Kyma runtime
Patchday
2021-12
Released on
2021/12/21

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Kyma

 

Related note
2484231
CVSS
4.3

Affected system type
ABAP
Patchday
2021-12
Released on
2021/12/14

Description
Missing Authorization Check in DIMP Industry Solution (Equipment and Tools Management & Bills of Services)

 

Related note
3102769
CVSS
8.8

Affected system type
Java
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-42063] Cross-Site Scripting (XSS) vulnerability in SAP Knowledge Warehouse

 

Related note
3130521
CVSS
9.9

Affected system type
Java
Patchday
2021-12
Released on
2021/12/16

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration

 

Related note
3132162
CVSS
10.0

Affected system type
SAP API Management
Patchday
2021-12
Released on
2021/12/24

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP API Management (Tenant Cloning Tool)

 

Related note
3107332
CVSS
6.6

Affected system type
SAP Landscape Management
Patchday
2021-12
Released on
2021/12/14

Description
Missing Authorization Check in SAP Landscape Management

 

Related note
3113593
CVSS
7.5

Affected system type
SAP Commerce
Patchday
2021-12
Released on
2021/12/14

Description
Denial of service (DOS) in SAP Commerce

 

Related note
3132074
CVSS
8.0

Affected system type
SAP Cloud for Customer
Patchday
2021-12
Released on
2021/12/23

Description
[CVE-2021-44228] Code Injection vulnerability in Cloud for Customer Lotus Notes PlugIn

 

Related note
2460948
CVSS
5.3

Affected system type
ABAP
Patchday
2021-12
Released on
2021/11/23

Description
Missing Authorization Check in Vehicle Management System

 

Related note
3121165
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-12
Released on
2021/12/14

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
2607126
CVSS
6.3

Affected system type
Java
Patchday
2021-11
Released on
2021/11/09

Description
Cross-Site Request Forgery vulnerability in Enterprise Services Repository of SAP Process Integration

 

Related note
3106859
CVSS
4.3

Affected system type
ABAP
Patchday
2021-11
Released on
2021/11/09

Description
URL Redirection vulnerability in Offer Management

 

Related note
3104456
CVSS
6.5

Affected system type
ABAP
Patchday
2021-11
Released on
2021/11/09

Description
[CVE-2021-42062] Missing Authorization check in SAP ERP HCM

 

Related note
3080106
CVSS
6.8

Affected system type
SAP GUI / Frontend
Patchday
2021-11
Released on
2021/11/09

Description
[CVE-2021-40503] Information Disclosure in SAP GUI for Windows

 

Related note
3099776
CVSS
9.6

Affected system type
Kernel
Patchday
2021-11
Released on
2021/11/09

Description
[CVE-2021-40501] Missing Authorization check in ABAP Platform Kernel

 

Related note
3110328
CVSS
8.3

Affected system type
SAP Commerce
Patchday
2021-11
Released on
2021/11/09

Description
[CVE-2021-40502] Missing Authorization check in SAP Commerce

 

Related note
3105728
CVSS
4.9

Affected system type
ABAP
Patchday
2021-11
Released on
2021/11/09

Description
[CVE-2021-40504] Leverage of Permission in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
2827086
CVSS
7.9

Affected system type
SAP FRP
Patchday
2021-11
Released on
2021/11/09

Description
Several security vulnerabilities in FRP 5.4.0 and FR Engine 5.4.0

 

Related note
3080710
CVSS
6.5

Affected system type
ABAP
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-38181] Denial of service (DOS) in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3098917
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-40497] Information Disclosure in SAP BusinessObjects Analysis (edition for OLAP)

 

Related note
3077635
CVSS
7.8

Affected system type
SAP Success Factors
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-40498] Denial of service (DOS) in the SAP SuccessFactors Mobile Application for Android devices

 

Related note
3074819
CVSS
6.7

Affected system type
SAP Business One
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-38179] Information Disclosure in SAP Business One

 

Related note
3100882
CVSS
6.4

Affected system type
SAP Cloud Print Manager
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-40499] Code Injection vulnerability for SAP NetWeaver Application Server for ABAP (SAP Cloud Print Manager and SAPSprint)

 

Related note
3084937
CVSS
5.4

Affected system type
ABAP
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-38183] Cross-Site Scripting (XSS) vulnerability in cms Service of SAP NetWeaver

 

Related note
3055347
CVSS
6.1

Affected system type
SAP UI5
Patchday
2021-10
Released on
2021/10/12

Description
Cross-Site Scripting (XSS) vulnerability in SAPUI5

 

Related note
2655294
CVSS
5.3

Affected system type
ABAP
Patchday
2021-10
Released on
2021/10/12

Description
Missing Authorization check in SCM BAPIs

 

Related note
3097887
CVSS
9.1

Affected system type
ABAP
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-38178] Improper Authorization in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3079427
CVSS
6.5

Affected system type
SAP Business One
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-38180] CSV Injection in SAP Business One

 

Related note
2988956
CVSS
5.4

Affected system type
ABAP
Patchday
2021-10
Released on
2021/09/28

Description
Cross-Site Request Forgery (CSRF) vulnerability in S/4HANA OP2020, OP1909 in Import Financial Plan Data

 

Related note
3087254
CVSS
4.3

Affected system type
ABAP
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-40496] Improper Access Control in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3074693
CVSS
6.9

Affected system type
BI/BO platform
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-40500] Missing XML Validation in SAP BusinessObjects Business Intelligence Platform (Crystal Reports)

 

Related note
2988962
CVSS
5.4

Affected system type
ABAP
Patchday
2021-10
Released on
2021/09/28

Description
Cross-Site Request Forgery (CSRF) vulnerability for S/4HANA OP2020, OP1909 in Import Financial Plan Data

 

Related note
3099011
CVSS
5.3

Affected system type
ABAP
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-40495] Denial of Service (DOS) in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
3101406
CVSS
9.8

Affected system type
Java
Patchday
2021-10
Released on
2021/10/12

Description
Potential XML External Entity Injection Vulnerability in SAP Environmental Compliance

 

Related note
3089438
CVSS
9.1

Affected system type
ABAP
Patchday
2021-10
Released on
2021/09/20

Description
Missing transaction start (AU3) entries in the Security Audit Log

 

Related note
3082500
CVSS
6.5

Affected system type
ABAP
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38175] Information Disclosure in SAP Analysis for Microsoft Office

 

Related note
3068582
CVSS
5.4

Affected system type
ABAP
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38164] Missing Authorization check in in SAP ERP Financial Accounting / RFOPENPOSTING_FR

 

Related note
3068337
CVSS
3.5

Affected system type
ABAP
Patchday
2021-09
Released on
2021/09/14

Description
Reverse tabnabbing vulnerability in SAP Marketing Lead Nurture Stream

 

Related note
3070138
CVSS
5.3

Affected system type
SAP Business One
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-33686] Information Disclosure in SAP Business One

 

Related note
3069882
CVSS
4.3

Affected system type
SAP Business One
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-33688] SQL Injection vulnerability in SAP Business One

 

Related note
3051787
CVSS
7.5

Affected system type
ABAP Java HANA platform
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38177] Null Pointer Dereference vulnerability in SAP CommonCryptoLib

 

Related note
3075546
CVSS
4.3

Affected system type
SAP Business One
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-37532] Directory Listing Enabled in SAP Business One

 

Related note
3080567
CVSS
8.9

Affected system type
Kernel
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38162] HTTP Request Smuggling in SAP Web Dispatcher

 

Related note
3073891
CVSS
9.6

Affected system type
BCM platform
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-33672] Multiple vulnerabilities in SAP Contact Center

 

Related note
3082219
CVSS
4.8

Affected system type
Java
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-21489] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3081888
CVSS
9.9

Affected system type
Java
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-37531] Code Injection vulnerability in SAP NetWeaver Knowledge Management (XMLForms)

 

Related note
3084487
CVSS
9.9

Affected system type
Java
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38163] Unrestricted File Upload vulnerability in SAP NetWeaver (Visual Composer 7.0 RT)

 

Related note
3078609
CVSS
10.0

Affected system type
Java
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-37535] Missing Authorization check in SAP NetWeaver Application Server for Java (JMS Connector Service)

 

Related note
2308378
CVSS
4.3

Affected system type
ABAP
Patchday
2021-09
Released on
2021/09/14

Description
Missing Authorization check in Financial Accounting

 

Related note
3087791
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38174] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3069032
CVSS
6.5

Affected system type
SAP Business One
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-33685] Directory Traversal vulnerability in SAP Business One

 

Related note
3055180
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-33679] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI Workspace)

 

Related note
3060621
CVSS
6.1

Affected system type
SAP GUI / Frontend
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38150] Information disclosure in SAP Business Client

 

Related note
3089831
CVSS
9.9

Affected system type
ABAP
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38176] SQL Injection vulnerability in SAP NZDT Mapping Table Framework

 

Related note
3057378
CVSS
8.8

Affected system type
Kernel
Patchday
2021-08
Released on
2021/08/10

Description
Missing Authentication check in SAP Web Dispatcher

 

Related note
3002517
CVSS
6.3

Affected system type
ABAP
Patchday
2021-08
Released on
2021/06/08

Description
[CVE-2021-21473] Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3073450
CVSS
6.9

Affected system type
Java
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33691] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Development Infrastructure (Notification Service)

 

Related note
3062085
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33696] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Crystal Report)

 

Related note
3072955
CVSS
9.9

Affected system type
Java
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33690] Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure (Component Build Service)

 

Related note
3078072
CVSS
6.3

Affected system type
SAP Business One
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33704] Missing Authorization Check in SAP Business One (Service Layer)

 

Related note
3078312
CVSS
9.1

Affected system type
ABAP
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33701] SQL Injection vulnerability in SAP NZDT Row Count Reconciliation

 

Related note
3072920
CVSS
8.3

Affected system type
Java
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33703] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
2659604
CVSS
6.4

Affected system type
ABAP
Patchday
2021-08
Released on
2021/07/27

Description
Cross-Site Scripting (XSS) Vulnerability in BSP application CRM_CM

 

Related note
3073325
CVSS
7.0

Affected system type
SAP Business One
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33700] Missing Authentication check in SAP Business One

 

Related note
3076399
CVSS
6.1

Affected system type
Java
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33707] URL Redirection vulnerability in SAP NetWeaver (Knowledge Management)

 

Related note
3058553
CVSS
6.8

Affected system type
SAP Cloud Connector
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33695] Multiple Vulnerabilities in SAP Cloud Connector

 

Related note
3063048
CVSS
4.7

Affected system type
BI/BO platform
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33697] Reverse Tabnabbing in SAP BusinessObjects Business Intelligence Platform (SAP UI5)

 

Related note
3067219
CVSS
7.6

Affected system type
SAP Fiori Client Android
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33699] Task Hijacking in SAP Fiori Client Native Mobile for Android

 

Related note
3074844
CVSS
8.1

Affected system type
Java
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33705] Server-Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3071984
CVSS
9.9

Affected system type
SAP Business One
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33698] Unrestricted File Upload vulnerability in SAP Business One

 

Related note
3073681
CVSS
8.3

Affected system type
Java
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33702] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
2675775
CVSS
6.3

Affected system type
ABAP
Patchday
2021-08
Released on
2021/08/10

Description
Switchable Authorization checks for RFC in CRM Middleware

 

Related note
3044754
CVSS
6.5

Affected system type
ABAP
Patchday
2021-07
Released on
2021/07/13

Description
[CVE-2021-33677] Information Disclosure in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3053403
CVSS
5.4

Affected system type
SAP Lumira Server
Patchday
2021-07
Released on
2021/07/13

Description
[CVE-2021-33682] Cross-Site Scripting (XSS) vulnerability in SAP Lumira Server

 

Related note
3038594
CVSS
3.5

Affected system type
Java
Patchday
2021-07
Released on
2021/07/13

Description
[CVE-2021-33689] Insufficient Logging in SAP NetWeaver AS for JAVA (Administrator)

 

Related note
3056652
CVSS
7.5

Affected system type
Java
Patchday
2021-07
Released on
2021/07/13

Description
[CVE-2021-33670] Denial of Service (DoS) in SAP NetWeaver AS for Java (Http Service)

 

Related note
3007182
CVSS
9.0

Affected system type
ABAP
Patchday
2021-07
Released on
2021/06/08

Description
[CVE-2021-27610] Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform

 

Related note
3059446
CVSS
7.6

Affected system type
Java
Patchday
2021-07
Released on
2021/07/13

Description
[CVE-2021-33671] Missing Authorization check in SAP NetWeaver Guided Procedures

 

Related note
3032624
CVSS
5.3

Affected system type
Kernel
Patchday
2021-07
Released on
2021/07/13

Description
[CVE-2021-33684] Memory Corruption in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3044751
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2021-07
Released on
2021/07/13

Description
[CVE-2021-33667] Information Disclosure in SAP Business Objects Web Intelligence (BI Launchpad)

 

Related note
3067890
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-07
Released on
2021/07/13

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3000663
CVSS
5.4

Affected system type
Kernel
Patchday
2021-07
Released on
2021/07/13

Description
[CVE-2021-33683] HTTP Request Smuggling in SAP Web Dispatcher and Internet Communication Manager

 

Related note
3059764
CVSS
4.5

Affected system type
Java
Patchday
2021-07
Released on
2021/07/13

Description
[CVE-2021-33687] Information Disclosure in SAP NetWeaver AS for Java (Enterprise Portal)

 

Related note
3048657
CVSS
6.5

Affected system type
ABAP
Patchday
2021-07
Released on
2021/07/13

Description
[CVE-2021-33678] Code Injection vulnerability in SAP NetWeaver AS ABAP (Reconciliation Framework)

 

Related note
3066316
CVSS
6.8

Affected system type
ABAP
Patchday
2021-07
Released on
2021/07/13

Description
[CVE-2021-33676] Missing authorization check in SAP CRM ABAP

 

Related note
3053066
CVSS
8.7

Affected system type
Java
Patchday
2021-06
Released on
2021/06/08

Description
[CVE-2021-27635] Missing XML Validation in SAP NetWeaver AS for JAVA

 

Related note
2999590
CVSS
4.3

Affected system type
ABAP
Patchday
2021-06
Released on
2021/05/25

Description
Incomplete authorization checks for import of environmental data

 

Related note
3025604
CVSS
5.4

Affected system type
ABAP
Patchday
2021-06
Released on
2021/06/08

Description
[CVE-2021-33664] Cross-Site Scripting (XSS) vulnerability within SAP NetWeaver AS ABAP (Applications based on Web Dynpro ABAP)

 

Related note
3028370
CVSS
5.4

Affected system type
ABAP
Patchday
2021-06
Released on
2021/06/08

Description
[CVE-2021-33665] Cross-Site Scripting (XSS) vulnerability within SAP NetWeaver AS ABAP (Applications based on SAP GUI for HTML)

 

Related note
3030604
CVSS
5.8

Affected system type
ABAP
Patchday
2021-06
Released on
2021/06/08

Description
[CVE-2021-33663] Plaintext Injection in SAP NetWeaver AS for ABAP

 

Related note
3030961
CVSS
6.4

Affected system type
Java
Patchday
2021-06
Released on
2021/06/08

Description
[CVE-2021-27615] Cross-Site Scripting (XSS) vulnerability in SAP Manufacturing Execution

 

Related note
2985562
CVSS
4.7

Affected system type
SAP Commerce Cloud
Patchday
2021-06
Released on
2021/06/08

Description
[CVE-2021-33666] Cross-Site Scripting (XSS) in SAP Commerce Cloud

 

Related note
3021050
CVSS
5.9

Affected system type
Internet Graphics Service
Patchday
2021-06
Released on
2021/06/08

Description
[Multiple CVEs] Memory Corruption vulnerability in SAP Internet Graphics Service

 

Related note
3049879
CVSS
5.9

Affected system type
SAP Enable Now
Patchday
2021-06
Released on
2021/06/08

Description
[CVE-2021-27637] Information Disclosure in SAP Enable Now (SAP Workforce Performance Builder - Manager)

 

Related note
3023078
CVSS
3.4

Affected system type
SAP GUI / Frontend
Patchday
2021-05
Released on
2021/05/11

Description
[CVE-2021-27612] SAP GUI for Windows is vulnerable to redirect users to an untrusted website

 

Related note
3049661
CVSS
7.8

Affected system type
SAP Business One
Patchday
2021-05
Released on
2021/05/11

Description
[CVE-2021-27616] Multiple vulnerabilities in SAP Business One, version for SAP HANA (Business-One-Hana-Chef-Cookbook)

 

Related note
2904569
CVSS
4.6

Affected system type
SAP CRM UI
Patchday
2021-05
Released on
2021/04/27

Description
Cross-Site Request Forgery (CSRF) vulnerability in SAP CRM WebClient UI

 

Related note
3012021
CVSS
4.9

Affected system type
Java
Patchday
2021-05
Released on
2021/05/11

Description
[Multiple CVEs] Multiple vulnerabilities in SAP Process Integration (Integration Builder Framework)

 

Related note
2745860
CVSS
5.3

Affected system type
Java
Patchday
2021-05
Released on
2021/05/11

Description
Information Disclosure in Enterprise Services Repository of SAP Process Integration

 

Related note
3039818
CVSS
6.5

Affected system type
SAP Commerce Cloud
Patchday
2021-05
Released on
2021/05/11

Description
[CVE-2021-27619] Information Disclosure in SAP Commerce (Backoffice search)

 

Related note
3049755
CVSS
7.8

Affected system type
SAP Business One
Patchday
2021-05
Released on
2021/05/11

Description
[CVE-2021-27613] Information Disclosure in SAP Business One (Chef business-one-cookbook)

 

Related note
3046610
CVSS
8.2

Affected system type
ABAP
Patchday
2021-05
Released on
2021/05/11

Description
[CVE-2021-27611] Code Injection vulnerability in SAP NetWeaver AS ABAP

 

Related note
2114798
CVSS
6.3

Affected system type
ABAP
Patchday
2021-05
Released on
2021/04/27

Description
Unauthorized use of application functions in SAP GUI for HTML

 

Related note
2818965
CVSS
4.6

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
Clickjacking vulnerability in Runtime Workbench of SAP Process Integration

 

Related note
2911863
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2021-04
Released on
2021/04/13

Description
Information Disclosure in BOE/CMC application

 

Related note
3035472
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-04
Released on
2021/03/18

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3025054
CVSS
4.3

Affected system type
ABAP
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27605 ] Missing Authorization check in HCM Travel Management Fiori Apps V2

 

Related note
3027937
CVSS
6.5

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27598] Improper Access Control in SAP NetWeaver AS for Java (Customer Usage Provisioning Servlet)

 

Related note
3036679
CVSS
5.3

Affected system type
ABAP
Patchday
2021-04
Released on
2021/04/13

Description
Update 1 to Security Note 1576763: Potential information disclosure relating to usernames

 

Related note
3012277
CVSS
6.5

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27599] Information Disclosure in SAP Process Integration (Integration Builder Framework)

 

Related note
3025637
CVSS
4.3

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-21492] Content spoofing in NetWeaver AS Java HTTP Service

 

Related note
3017823
CVSS
8.2

Affected system type
SAP Solution Manager
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-21483] Information Disclosure in SAP Solution Manager

 

Related note
3028729
CVSS
6.5

Affected system type
ABAP
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27603] Denial of Service (DoS) in SAP NetWeaver AS of ABAP

 

Related note
3017908
CVSS
8.3

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-21482] Information Disclosure in SAP NetWeaver Master Data Management

 

Related note
2963592
CVSS
5.4

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27601] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java (Applications based on HTMLB for Java)

 

Related note
3040210
CVSS
9.9

Affected system type
SAP Commerce / SAP...
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27602] Remote Code Execution vulnerability in Source Rules of SAP Commerce

 

Related note
3039649
CVSS
7.5

Affected system type
SAP GUI / Frontend
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27608] Unquoted Search Path in SAPSetup

 

Related note
3024414
CVSS
6.4

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27600 ] Cross-Site Scripting (XSS) vulnerability in SAP Manufacturing Execution (System Rules)

 

Related note
3001824
CVSS
7.4

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-21485] Information Disclosure in SAP NetWeaver AS for Java (Telnet Commands)

 

Related note
3005802
CVSS
5.4

Affected system type
ABAP
Patchday
2021-04
Released on
2021/03/23

Description
Cross-Site Request Forgery (CSRF) vulnerability in S/4HANA Finance for advanced payment management

 

Related note
3030948
CVSS
4.6

Affected system type
SAP Solution Manager...
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27609] Missing Authorization check in SAP Focused RUN

 

Related note
3036436
CVSS
6.5

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27604] Potential XXE Vulnerability in SAP Process Integration (ESR Java Mappings)

 

Related note
3022422
CVSS
9.6

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21481] Missing Authorization Check in SAP NetWeaver AS JAVA (MigrationService)

 

Related note
2976947
CVSS
4.7

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21491] Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on Web Dynpro Java)

 

Related note
2977001
CVSS
4.7

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on HTMLB for Java)

 

Related note
3022622
CVSS
9.9

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence

 

Related note
3017378
CVSS
7.7

Affected system type
SAP HANA Platform
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21484] Possible authentication bypass in SAP HANA LDAP scenarios

 

Related note
2475705
CVSS
6.3

Affected system type
ABAP
Patchday
2021-03
Released on
2021/02/23

Description
Switchable Authorization checks for RFC in In House Cash

 

Related note
3027767
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-27592] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3007888
CVSS
6.8

Affected system type
ABAP
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21486] Missing Authorization check in SAP Enterprise Financial Services( Bank Customer Accounts )

 

Related note
3023778
CVSS
6.8

Affected system type
ABAP
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21487] Missing Authorization Check in Payment Engine

 

Related note
2983436
CVSS
6.5

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21488] Insecure deserialisation in SAP NetWeaver Knowledge Management

 

Related note
2978151
CVSS
4.7

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
Reverse tabnabbing issue in Unified Rendering based frameworks in NetWeaver Application Server Java

 

Related note
3027758
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-03
Released on
2021/03/09

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
2998173
CVSS
6.3

Affected system type
SAP Netweaver
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21472] Server password not set during installation of SAP NetWeaver Master Data Management 7.1

 

Related note
2935791
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21444] Clickjacking vulnerability in SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad)

 

Related note
2973428
CVSS
4.7

Affected system type
Kernel
Patchday
2021-02
Released on
2021/02/09

Description
Reverse Tabnabbing vulnerability within SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML)

 

Related note
3014121
CVSS
9.9

Affected system type
SAP Commerce Cloud
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21477] Remote Code Execution vulnerability in SAP Commerce

 

Related note
2818963
CVSS
0.0

Affected system type
Java
Patchday
2021-02
Released on
2021/02/09

Description
Clickjacking vulnerability in Adapter Runtime of SAP Process Integration

 

Related note
3000897
CVSS
4.0

Affected system type
Java
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21475] Directory Traversal vulnerability in SAP NetWeaver Master Data Management 7.1

 

Related note
2835240
CVSS
5.4

Affected system type
Java
Patchday
2021-02
Released on
2021/02/09

Description
Clickjacking vulnerability in Cloud Integration Content of SAP Process Integration

 

Related note
2992154
CVSS
4.1

Affected system type
SAP HANA Platform
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21474] SAML Assertion Signature MD5 Digest Algorithm Vulnerability in SAP HANA Database

 

Related note
2990992
CVSS
5.4

Affected system type
ABAP
Patchday
2021-02
Released on
2021/02/09

Description
Missing Authorization Checks in the Monitor Data and My Data Collections Apps

 

Related note
2994289
CVSS
4.1

Affected system type
ABAP
Patchday
2021-02
Released on
2021/02/09

Description
Reverse Tabnabbing vulnerability within SAP CRM WebClient UI

 

Related note
2974582
CVSS
4.7

Affected system type
ABAP
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21478] Reverse Tabnabbing vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP)

 

Related note
2992269
CVSS
5.3

Affected system type
SAP GUI / Frontend
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21448] Information Disclosure in SAP GUI for Windows

 

Related note
2984034
CVSS
5.4

Affected system type
SAP Commerce Cloud
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21445] Header Manipulation vulnerability in SAP Commerce Cloud

 

Related note
3002617
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-01
Released on
2021/01/12

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
2999854
CVSS
9.9

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21466] Code Injection in SAP Business Warehouse and SAP BW/4HANA

 

Related note
2986980
CVSS
9.9

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21465] Multiple vulnerabilities in SAP Business Warehouse (Database Interface)

 

Related note
3000306
CVSS
7.5

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21446] Denial of service (DOS) in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
2743329
CVSS
6.3

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
Switchable authorization checks for RFC module in In-House-Cash.

 

Related note
3001373
CVSS
8.9

Affected system type
Cloud Foundry
Patchday
2021-01
Released on
2020/12/22

Description
Information Disclosure in Central Order

 

Related note
2665387
CVSS
5.5

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
Cross-Site Request Forgery (CSRF) vulnerability in Cash Management

 

Related note
3008422
CVSS
4.3

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21467] Missing Authorization check in SAP Banking Services (Generic Market Data)

 

Related note
2965154
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21447] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)

 

Related note
3000291
CVSS
3.6

Affected system type
Analysis for Office
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21470] XML External Entity vulnerability in SAP EPM add-in

 

Related note
2993032
CVSS
5.3

Affected system type
Java
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21469] Information Disclosure in SAP NetWeaver Master Data Management

 

Related note
2989075
CVSS
9.6

Affected system type
BI/BO platform
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26831] Missing XML Validation in SAP BusinessObjects Business Intelligence Platform (Crystal Report)

 

Related note
2996479
CVSS
5.3

Affected system type
ABAP
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26835] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP

 

Related note
2974774
CVSS
10.0

Affected system type
Java
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26829] Missing Authentication Check in SAP NetWeaver AS JAVA (P2P Cluster Communication)

 

Related note
2971180
CVSS
5.4

Affected system type
SAP Disclosure Management
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26828] Formula Injection in SAP Disclosure Management

 

Related note
2971163
CVSS
5.4

Affected system type
Java
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26816] Missing Encryption in SAP NetWeaver AS Java (Key Storage Service)

 

Related note
2993132
CVSS
7.6

Affected system type
ABAP
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26832] Missing Authorization check in SAP NetWeaver AS ABAP and SAP S4 HANA (SAP Landscape Transformation)

 

Related note
2983367
CVSS
9.1

Affected system type
ABAP
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26838] Code Injection vulnerability in SAP Business Warehouse (Master Data Management) and SAP BW4HANA

 

Related note
2938650
CVSS
3.4

Affected system type
ABAP
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26836] Open Redirect in SAP Solution Manager (Trace Analysis)

 

Related note
2983204
CVSS
8.5

Affected system type
SAP Solution Manager
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26837] Multiple Vulnerabilities in SAP Solution Manager 7.2 (User Experience Monitoring)

 

Related note
2974330
CVSS
6.5

Affected system type
Java
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26826] Unrestricted File Upload vulnerability in SAP NetWeaver Application Server for Java (Process Integration Monitoring)

 

Related note
2989719
CVSS
6.3

Affected system type
ABAP
Patchday
2020-12
Released on
2020/11/24

Description
Missing Authorization check in S/4HANA (Central Finance)

 

Related note
2978768
CVSS
4.2

Affected system type
HANA Platform
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26834 ] Improper authentication in SAP HANA database

 

Related note
2971954
CVSS
6.5

Affected system type
ABAP
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26818] Multiple vulnerabilities in SAP NetWeaver AS ABAP (Web Dynpro)

 

Related note
2979062
CVSS
9.1

Affected system type
Java
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26820] Privilege escalation in SAP NetWeaver Application Server for Java (UDDI Server)

 

Related note
2971112
CVSS
4.4

Affected system type
SAP ERP Client for E-Bilanz
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26807] Incorrect Default Permissions in SAP ERP Client for E-Bilanz 1.0

 

Related note
2975189
CVSS
7.5

Affected system type
SAP Commerce Cloud
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26809] Information Disclosure in SAP Commerce Cloud

 

Related note
2985866
CVSS
10.0

Affected system type
Java
Patchday
2020-11
Released on
2020/11/10

Description
[Multiple CVE IDs] Missing Authentication Check in SAP Solution Manager (JAVA stack)

 

Related note
2973735
CVSS
9.1

Affected system type
ABAP
Patchday
2020-11
Released on
2020/11/11

Description
[CVE-2020-26808] Code Injection in SAP AS ABAP and S/4 HANA (DMIS)

 

Related note
2264508
CVSS
5.4

Affected system type
ABAP
Patchday
2020-11
Released on
2020/10/27

Description
SQL Injection in SAF-T Portugal

 

Related note
2975170
CVSS
7.5

Affected system type
SAP Commerce Cloud
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26810] Multiple Vulnerabilities in SAP Commerce Cloud (Accelerator Payment Mock)

 

Related note
2944188
CVSS
4.3

Affected system type
ABAP
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-6316] Missing Authorization Check in SAP ERP and SAP S/4 HANA

 

Related note
2319577
CVSS
5.4

Affected system type
ABAP
Patchday
2020-11
Released on
2020/10/27

Description
SQL Injection in SAF-T Portugal

 

Related note
2984627
CVSS
8.6

Affected system type
ABAP
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26815] Security Vulnerabilities in SAP Fiori Launchpad (NewsTile Application)

 

Related note
2947891
CVSS
3.0

Affected system type
ABAP
Patchday
2020-11
Released on
2020/11/10

Description
Missing Authorization check in Disbursement Read API used in Read Disbursement Webservice

 

Related note
2824209
CVSS
5.4

Affected system type
Java
Patchday
2020-11
Released on
2020/11/10

Description
Clickjacking vulnerability in SAP Process Integration (Integration Builder Framework)

 

Related note
2982840
CVSS
9.8

Affected system type
SAP Data Services
Patchday
2020-11
Released on
2020/11/10

Description
Multiple Vulnerabilities in SAP Data Services

 

Related note
2952084
CVSS
4.9

Affected system type
Java
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26814] Information Disclosure in SAP Process Integration (PGP Module – Business-to-Business Add On)

 

Related note
2985094
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26817] Improper input validation in Visual Enterprise Viewer

 

Related note
2945581
CVSS
4.7

Affected system type
SAP CRM UI
Patchday
2020-10
Released on
2020/09/22

Description
Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI

 

Related note
2873099
CVSS
5.4

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
Missing Authorization check in EHS Task Definition attachments

 

Related note
2953212
CVSS
4.3

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6362] Incorrect Authorization in SAP Banking Services

 

Related note
2971638
CVSS
7.5

Affected system type
SAP Solution Manager...
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6369] Hard-coded Credentials in CA Introscope Enterprise Manager (Affected products: SAP Solution Manager and SAP Focused Run)

 

Related note
2939419
CVSS
4.8

Affected system type
SAP NetWeaver...
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6370] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (DI Design Time Repository)

 

Related note
2973100
CVSS
3.6

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
Missing Authorization check in Manage Substitutions - Products and Manage Exclusions - Products

 

Related note
2943844
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6308] Server-Side Request Forgery vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Services)

 

Related note
2606194
CVSS
4.4

Affected system type
ABAP
Patchday
2020-10
Released on
2020/09/09

Description
Cross-Site Scripting (XSS) vulnerability in CRM Interaction Center

 

Related note
2969828
CVSS
10.0

Affected system type
Solution Manager
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6364] OS Command Injection Vulnerability in CA Introscope Enterprise Manager (Affected Products: SAP Solution Manager and SAP Focused Run)

 

Related note
2956398
CVSS
6.1

Affected system type
Java
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6319] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java

 

Related note
2965315
CVSS
4.7

Affected system type
Java
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6365] Reverse Tabnabbing vulnerability in SAP NetWeaver AS Java Start Page

 

Related note
2917381
CVSS
5.4

Affected system type
SAP Commerce Cloud
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6272] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Cloud

 

Related note
2972661
CVSS
8.2

Affected system type
Java
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6367] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Composite Application Framework

 

Related note
2883638
CVSS
6.5

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
Information Disclosure in Supplier Relationship Management

 

Related note
2960825
CVSS
5.4

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6368] Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation

 

Related note
2963137
CVSS
4.3

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6371] Information disclosure in SAP NetWeaver AS ABAP via the POWL Test Feeder endpoint

 

Related note
2965287
CVSS
3.7

Affected system type
SAP Commerce Cloud
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6363] Insufficient Session Expiration in SAP Commerce Cloud

 

Related note
2969457
CVSS
7.6

Affected system type
Java
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6366] Missing XML Validation in SAP NetWeaver (Compare Systems)

 

Related note
2960329
CVSS
4.4

Affected system type
SAP Enterprise Portal...
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6323] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (Fiori Framework Page)

 

Related note
2973497
CVSS
5.7

Affected system type
SAP 3D Visual Enterprise
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6315] Multiple Vulnerabilities in SAP 3D Visual Enterprise Viewer

 

Related note
2955963
CVSS
4.3

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
Cross-Site Request Forgery (CSRF) in SAP Marketing

 

Related note
2960815
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2020-09
Released on
2020/09/08

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
2953112
CVSS
5.4

Affected system type
Java
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6326] Cross-Site Scripting (XSS) vulnerabilities in SAP NetWeaver AS Java

 

Related note
2934451
CVSS
6.4

Affected system type
SAP Commerce Cloud
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6302] Session Fixation in SAP Commerce

 

Related note
2951325
CVSS
6.5

Affected system type
ABAP
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6311] Improper Authorization Checks in Banking services from SAP Bank Analyzer and SAP S/4HANA Financial Products

 

Related note
2948239
CVSS
6.1

Affected system type
ABAP
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6324] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Test Application)

 

Related note
2961991
CVSS
9.6

Affected system type
SAP Marketing
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6320] Improper Access Control in SAP Marketing (Mobile Channel Servlet)

 

Related note
2953203
CVSS
2.6

Affected system type
SAP Adaptive Server...
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6317] Information Disclosure in SAP Adaptive Server Enterprise

 

Related note
2865229
CVSS
4.8

Affected system type
SAP UI5
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6283] Cross-Site Scripting (XSS) vulnerability in SAP Fiori(Launchpad)

 

Related note
2924859
CVSS
6.5

Affected system type
ABAP
Patchday
2020-09
Released on
2020/08/25

Description
Missing Authorization check in Discrete Industries and Mill Products

 

Related note
2958563
CVSS
9.1

Affected system type
ABAP
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6318] Code Injection vulnerability in SAP NetWeaver (ABAP Server) and ABAP Platform

 

Related note
2930128
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6325] Multiple Vulnerabilities in SAP BusinessObjects Business Intelligence Platform

 

Related note
2531082
CVSS
6.3

Affected system type
ABAP
Patchday
2020-09
Released on
2019/03/12

Description
Switchable Authorization checks for RFC BCA_DIM_LOANS_APPLOG_UPDATE in Loans (FI-CAX-FS)

 

Related note
2754546
CVSS
5.0

Affected system type
Lumira Designer
Patchday
2020-08
Released on
2020/08/11

Description
Potential information disclosure in Lumira Designer

 

Related note
2927956
CVSS
8.5

Affected system type
BI/BO platform
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6294] Missing Authentication check in SAP BusinessObjects Business Intelligence Platform

 

Related note
2756551
CVSS
6.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
Missing Authorization check in TSW Supply Chain Visualization

 

Related note
2593479
CVSS
3.9

Affected system type
Java
Patchday
2020-08
Released on
2018/06/15

Description
Checking server certificates and host name of managed systems

 

Related note
2939685
CVSS
8.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6298] Missing Authorization check in SAP Banking Services (Generic Market Data)

 

Related note
2925827
CVSS
4.8

Affected system type
BI/BO platform
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6300] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(Central Management Console)

 

Related note
2941667
CVSS
8.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6296] Code Injection Vulnerability in SAP NetWeaver (ABAP) and ABAP Platform

 

Related note
2941332
CVSS
7.0

Affected system type
SAP Adaptive Server...
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6295] Information Disclosure in SAP Adaptive Server Enterprise

 

Related note
2941510
CVSS
4.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6299] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform

 

Related note
2949196
CVSS
5.4

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6301] Missing Authorization check in SAP ERP (HCM Travel Management)

 

Related note
2948317
CVSS
6.1

Affected system type
SAP Commerce
Patchday
2020-08
Released on
2020/08/11

Description
Vulnerabilities in open source libraries used in SAP Commerce

 

Related note
2928635
CVSS
9.0

Affected system type
Java
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6284] Cross-Site Scripting (XSS) in SAP NetWeaver (Knowledge Management)

 

Related note
2941170
CVSS
6.1

Affected system type
SAP GUI / Frontend
Patchday
2020-08
Released on
2020/08/11

Description
Cross-Site Scripting (XSS) vulnerabilities in modified jQuery bundled with SAPUI5

 

Related note
2885671
CVSS
4.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6273] Missing Authorization check in SAP S/4 HANA (Fiori UI for General Ledger Accounting)

 

Related note
2938162
CVSS
7.3

Affected system type
Java
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6293] Unrestricted File Upload in SAP NetWeaver (Knowledge Management)

 

Related note
2941315
CVSS
7.5

Affected system type
Java
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6309] Missing Authentication check in SAP NetWeaver AS JAVA

 

Related note
2921615
CVSS
5.5

Affected system type
BI/BO platform
Patchday
2020-08
Released on
2020/08/11

Description
BI Platform stores SAP BW Authentication Password as clear text

 

Related note
2944988
CVSS
4.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6310] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform

 

Related note
2940823
CVSS
6.3

Affected system type
SAP Data Hub
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6297] Information Disclosure in SAP Data Intelligence

 

Related note
2932473
CVSS
7.7

Affected system type
Java
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6285] Information Disclosure in SAP NetWeaver (XMLToolkit for Java)

 

Related note
2486446
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Missing Authorization check in Pricat Inbound and Pricat Outbound

 

Related note
2927373
CVSS
2.7

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6280] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform

 

Related note
2847817
CVSS
4.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Missing Authorization check in Travel Management

 

Related note
2537961
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Switchable Authorization checks for RFC in MM-PUR-GF

 

Related note
2758000
CVSS
6.3

Affected system type
SAP Disclosure Management
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6267] Multiple vulnerabilities in SAP Disclosure Management

 

Related note
2603398
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Missing authorization check in Allocation Management

 

Related note
2938831
CVSS
6.0

Affected system type
ABAP
Patchday
2020-07
Released on
2020/06/23

Description
SESS: Duplicate AU3 entries in the Security Audit Log

 

Related note
2091403
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2015/08/11

Description
Directory traversal in BC-MID-ICF

 

Related note
2917743
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6281] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(BI Launch pad)

 

Related note
2912708
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6278] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC)

 

Related note
2874738
CVSS
3.8

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Missing Authorization Check in S4 ACR Brazil Option

 

Related note
2934135
CVSS
10.0

Affected system type
Java
Exploit available
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6287] Multiple Vulnerabilities in SAP NetWeaver AS JAVA (LM Configuration Wizard)

 

Related note
2849967
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6276] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(Bipodata)

 

Related note
2541823
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/06/09

Description
Switchable authorization checks for RFC in SAP CRM (external billing)

 

Related note
2896025
CVSS
5.8

Affected system type
Java
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6282] Server-Side Request Forgery in SAP NetWeaver AS JAVA (IIOP service)

 

Related note
2911267
CVSS
4.3

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
Update 1 to Security Note 2752614 - [CVE-2019-0319] Content Injection Vulnerability in SAP Gateway

 

Related note
2878935
CVSS
6.1

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6246] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP ( Business Server Pages Test Application SBSPEXT_TABLE)

 

Related note
2928570
CVSS
9.8

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
Ghostcat' Apache Tomcat AJP Vulnerability in SAP Liquidity Management for Banking

 

Related note
2908382
CVSS
4.4

Affected system type
SAP Business One
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6239] Information Disclosure in SAP Business One (Backup Service)

 

Related note
2931391
CVSS
8.2

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6271] Missing XML Validation in SAP Solution Manager (Problem Context Manager)

 

Related note
2923035
CVSS
4.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI

 

Related note
2906996
CVSS
5.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6268] Missing authorization check in SAP ERP (Statutory Reporting for Insurance Companies)

 

Related note
2906366
CVSS
8.6

Affected system type
SAP Cloud Commerce
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6264] Information Disclosure in SAP Commerce

 

Related note
2918762
CVSS
6.5

Affected system type
Adobe LiveCycle Designer
Patchday
2020-06
Released on
2020/06/09

Description
Multiple vulnerabilities in Adobe LiveCycle Designer 11.0

 

Related note
2918924
CVSS
9.8

Affected system type
SAP Cloud Commerce
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6265] Use of Hard-coded Credentials in SAP Commerce and SAP Commerce Datahub

 

Related note
2915126
CVSS
6.5

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6260] Incomplete XML Validation in SAP Solution Manager (Trace Analysis)

 

Related note
2911704
CVSS
5.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA

 

Related note
2905836
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6269] Information Disclosure in SAP Business Objects Business Intelligence Platform

 

Related note
2540180
CVSS
6.3

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
Switchable Authorization checks for RFC in Environment, Health & Safety

 

Related note
2878568
CVSS
6.9

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6263] Authentication Bypass in Standalone Clients connecting to SAP NetWeaver AS Java via P4 Protocol

 

Related note
2916562
CVSS
6.5

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6270] Missing Authorization check in SAP Netweaver AS ABAP (Banking Services)

 

Related note
2912939
CVSS
7.6

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6275] Server Side Request Forgery vulnerability in SAP NetWeaver AS ABAP

 

Related note
2911687
CVSS
5.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA

 

Related note
2917090
CVSS
9.0

Affected system type
SAP Adaptive Server...
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6252] Information Disclosure in SAP Adaptive Server Enterprise (Cockpit)

 

Related note
2913293
CVSS
6.1

Affected system type
SAP Enterprise Threat...
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6254] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Threat Detection

 

Related note
2835979
CVSS
9.9

Affected system type
ABAP
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6262] Code Injection vulnerability in Service Data Download

 

Related note
2920548
CVSS
6.5

Affected system type
SAP Adaptive Server...
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6259] Missing authorization check in SAP Adaptive Server Enterprise

 

Related note
2917275
CVSS
9.1

Affected system type
SAP Adaptive Server...
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6248] Code injection in SAP Adaptive Server Enterprise (Backup Server)

 

Related note
2917273
CVSS
7.2

Affected system type
SAP Adaptive Server...
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6253] SQL Injection vulnerability in SAP Adaptive Server Enterprise (Web Services)

 

Related note
2917022
CVSS
6.8

Affected system type
SAP Adaptive Server...
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6250] Information Disclosure in SAP Adaptive Server Enterprise

 

Related note
2916927
CVSS
8.8

Affected system type
SAP Adaptive Server...
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6241] SQL Injection vulnerability in SAP Adaptive Server Enterprise

 

Related note
2915585
CVSS
8.0

Affected system type
SAP Adaptive Server...
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6243] Code Injection in SAP Adaptive Server Enterprise (XP Server on Windows Platform)

 

Related note
2915429
CVSS
4.3

Affected system type
SAP IDM
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6258] Missing Authorization check in SAP Identity Management

 

Related note
2747062
CVSS
5.0

Affected system type
ABAP
Patchday
2020-05
Released on
2020/05/12

Description
This note has been re-released without changes. - Cross-Site Request Forgery (CSRF) vulnerability in SAP Web Dynpro ABAP

 

Related note
2900118
CVSS
9.1

Affected system type
SAP Orient DB
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6230] Code Injection vulnerability in SAP OrientDB 3.0

 

Related note
2880804
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6222] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)

 

Related note
2872782
CVSS
6.1

Affected system type
ABAP
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6215] URL Redirection vulnerability in SAP NetWeaver AS ABAP – Business Server Pages Test Application IT00

 

Related note
2878507
CVSS
6.4

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6195] Multiple vulnerabilities in SAP Business Objects Business Intelligence Platform

 

Related note
2877226
CVSS
6.3

Affected system type
ABAP
Patchday
2020-04
Released on
2020/03/12

Description
Switchable Authorization checks in SAP Supplier Relationship Management

 

Related note
2902645
CVSS
7.2

Affected system type
SAP Host Agent
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6234] Privilege Escalation in SAP Host Agent

 

Related note
2900374
CVSS
6.1

Affected system type
ABAP
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6229] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME)

 

Related note
2863396
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6227] Remote unauthenticated log injection in SAP Business Objects Business Intelligence Platform (CMS / Auditing issues)

 

Related note
2863731
CVSS
9.1

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6219] Deserialization of Untrusted Data in SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer)

 

Related note
2879132
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6226] Cross-Site Scripting (XSS) vulnerabilities in SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface)

 

Related note
2888556
CVSS
5.3

Affected system type
SAP Commerce Cloud
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6232] Missing Authorization check in SAP Commerce

 

Related note
2872752
CVSS
6.1

Affected system type
ABAP
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6213]Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP(Business Server Pages Test Application SBSPEXT_PHTMLB)

 

Related note
2826528
CVSS
6.2

Affected system type
Java
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6224] Information Disclosure in SAP NetWeaver Application Server Java (HTTP Service)

 

Related note
2876059
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6216] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform (BILaunchpad/ Opendocument)

 

Related note
2866752
CVSS
5.3

Affected system type
SAP GUI / Frontend
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6228] Missing Integrity Check in SAP BUSINESS CLIENT

 

Related note
2904480
CVSS
9.3

Affected system type
SAP Commerce Cloud
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6238] Missing XML Validation vulnerability in SAP Commerce

 

Related note
2897612
CVSS
4.7

Affected system type
ABAP
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6214] Incorrect Authorization in SAP S/4HANA (Financial Products Subledger)

 

Related note
2904796
CVSS
4.3

Affected system type
ABAP
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6233] Missing Authorization Check in SAP S/4 HANA (Financial Products Subledger and Banking Services)

 

Related note
2864966
CVSS
6.3

Affected system type
ABAP
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6212] Missing Authorization Check in SAP ERP & S/4 HANA (Egypt localized Withholding Tax reports)

 

Related note
2896682
CVSS
9.1

Affected system type
Java
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6225] Directory Traversal vulnerability in SAP NetWeaver (Knowledge Management)

 

Related note
2906994
CVSS
8.6

Affected system type
SAP Solution Manager
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6235] Missing authentication check in SAP Solution Manager (Diagnostics Agent )

 

Related note
2872545
CVSS
6.1

Affected system type
ABAP
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6217] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (Business Server Pages Test Application IT05)

 

Related note
2898077
CVSS
7.5

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6237] Information Disclosure in SAP Business Objects Business Intelligence Platform (dswsbobje Web Application)

 

Related note
2902456
CVSS
7.2

Affected system type
SAP Landscape Management
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6236] Privilege Escalation in SAP Landscape Management (SAP Adaptive Extensions)

 

Related note
2845363
CVSS
3.8

Affected system type
SAP Enable Now
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6197] Insufficient session expiration in SAP Enable Now Manager

 

Related note
1966029
CVSS
7.3

Affected system type
ABAP
Patchday
2020-03
Released on
2020/03/10

Description
Directory traversal in SAP Environment Health and Safety

 

Related note
2892570
CVSS
5.9

Affected system type
ABAP Development Tools
Patchday
2020-03
Released on
2020/03/10

Description
Missing XML Validation vulnerability in ABAP Development Tools

 

Related note
2845377
CVSS
9.8

Affected system type
Java
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6198] Missing Authentication check in SAP Solution Manager (Diagnostics Agent)

 

Related note
2826782
CVSS
7.5

Affected system type
BI/BO platform
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6196] Denial of service (DOS) in SAP BusinessObjects Mobile (MobileBIService)

 

Related note
2841874
CVSS
4.3

Affected system type
ABAP
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6204] Missing Authorization check in SAP Treasury and Risk Management (Transaction Management)

 

Related note
2890213
CVSS
10.0

Affected system type
Java
Exploit available
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6207] Missing Authentication Check in SAP Solution Manager (User-Experience Monitoring)

 

Related note
2864462
CVSS
4.7

Affected system type
ABAP
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6210] Cross-Site Scripting (XSS) vulnerability in SAP Fiori Launchpad

 

Related note
2847787
CVSS
5.5

Affected system type
Java
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6202] Missing XML Validation in SAP NetWeaver Application Server Java (User Management Engine)

 

Related note
2806198
CVSS
9.1

Affected system type
Java
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6203] Path Manipulation in SAP NetWeaver UDDI Server(Services Registry)

 

Related note
2858044
CVSS
7.5

Affected system type
SAP Disclosure Management
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6209] Missing Authorization check in SAP Disclosure Management

 

Related note
2731871
CVSS
6.3

Affected system type
ABAP
Patchday
2020-03
Released on
2020/03/10

Description
Missing Authorization check in Commercial Project Management

 

Related note
2861301
CVSS
8.2

Affected system type
BI/BO platform
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6208] Remote Code Execution in SAP Business Objects Business Intelligence Platform (Crystal Reports)

 

Related note
2859004
CVSS
4.7

Affected system type
SAP CPI DS
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6206] Cross-Site Request Forgery in SAP Cloud Platform Integration for data services

 

Related note
2884910
CVSS
6.1

Affected system type
ABAP
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6205] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP Business Server Pages  (Smart Forms)

 

Related note
2876813
CVSS
6.1

Affected system type
SAP Commerce Cloud
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6201] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Cloud (testweb extension)

 

Related note
2876413
CVSS
5.4

Affected system type
SAP Commerce Cloud
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6200] Cross-Site-Scripting in SAP Commerce Cloud (SmartEdit extension)

 

Related note
2871167
CVSS
5.4

Affected system type
ABAP
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6199] Missing Authorization check in SAP ERP and S/4 HANA (MENA Certificate Management)

 

Related note
2880664
CVSS
5.4

Affected system type
SAP Enable Now
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6178] Insufficient session expiration in SAP Enable Now Manager

 

Related note
2660005
CVSS
7.2

Affected system type
SAP MaxDB
Patchday
2020-03
Released on
2018/08/14

Description
[CVE-2018-2450] SQL Injection Vulnerability in SAP MaxDB/liveCache

 

Related note
2836445
CVSS
5.3

Affected system type
SAP Host Agent
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6183] Unprivileged Access to technical data using SAPOSCOL of SAP Host Agent

 

Related note
2822074
CVSS
6.6

Affected system type
ABAP
Patchday
2020-02
Released on
2020/01/14

Description
Missing Authorization check in SAP NetWeaver (ABAP Server)

 

Related note
2873012
CVSS
6.1

Affected system type
Java
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6193]Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (Knowledge Management ICE Service)

 

Related note
2857511
CVSS
6.3

Affected system type
ABAP
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6188] Missing Authorization check in SAP ERP and S/4 HANA (VAT Pro-Rata reports)

 

Related note
2880744
CVSS
5.8

Affected system type
ABAP
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6181] HTTP Response Splitting vulnerability in SAP NetWeaver and ABAP Platform

 

Related note
2864415
CVSS
4.9

Affected system type
Java
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6187]Missing XML Validation vulnerability in SAP NetWeaver(Guided Procedures)

 

Related note
2878030
CVSS
7.2

Affected system type
SAP Landscape Management
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6191] Missing Input Validation in SAP Landscape Management

 

Related note
2838835
CVSS
5.3

Affected system type
Java
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6190]Information Disclosure in SAP NetWeaver AS Java (Heap Dump Application)

 

Related note
2736825
CVSS
6.5

Affected system type
ABAP
Patchday
2020-02
Released on
2019/03/12

Description
[CVE-2019-0271] Denial of Service via XML External Entity (XXE) vulnerability in ABAP Server

 

Related note
2880869
CVSS
6.1

Affected system type
ABAP
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6184 ]Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver and SAP S/4HANA

 

Related note
2057196
CVSS
6.3

Affected system type
ABAP
Patchday
2020-02
Released on
2014/09/17

Description
Missing authorization check in IS-B-BCA-AM

 

Related note
2877968
CVSS
7.2

Affected system type
SAP Landscape Management
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6192] Missing Input Validation in SAP Landscape Management

 

Related note
2880993
CVSS
4.3

Affected system type
SAP Mobile Platform
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6177] Missing XML Validation vulnerability in SAP Mobile Platform

 

Related note
2622660
CVSS
10.0

Affected system type
SAP GUI / Frontend
Patchday
2020-02
Released on
2018/04/10

Description
Security updates for the browser control Google Chromium delivered with SAP Business Client

 

Related note
2695210
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6189] Information Disclosure in SAP BusinessObjects BI Central Management Console

 

Related note
2695776
CVSS
7.4

Affected system type
SAP Mobile Platform
Patchday
2020-02
Released on
2020/01/14

Description
Missing Authorization Check in SAP Mobile Platform Native SDK, Android

 

Related note
2841053
CVSS
7.5

Affected system type
SAP Host Agent
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6186] Denial of Service (DOS) Vulnerability in SAP Host Agent

 

Related note
2870067
CVSS
6.5

Affected system type
ABAP
Patchday
2020-02
Released on
2020/02/11

Description
Update 1 to Security Note 2736825 - [CVE-2019-0271] Denial of Service via XML External Entity (XXE) vulnerability in ABAP Server

 

Related note
2688383
CVSS
6.3

Affected system type
ABAP
Patchday
2020-02
Released on
2020/02/11

Description
Missing authorization check in Dangerous Goods Management of EHS Services in SCM

 

Related note
2845401
CVSS
5.4

Affected system type
Realtech
Patchday
2020-01
Released on
2020/01/14

Description
Missing Authorization check in Realtech RTCISM 100

 

Related note
2495462
CVSS
6.3

Affected system type
ABAP
Patchday
2020-01
Released on
2020/01/14

Description
Switchable Authorization checks for RFC in SAP Leasing

 

Related note
2848498
CVSS
5.9

Affected system type
Kernel
Patchday
2020-01
Released on
2020/01/14

Description
[CVE-2020-6304] Denial of service (DOS) in SAP NetWeaver Internet Communication Manager

 

Related note
2142551
CVSS
4.3

Affected system type
ABAP
Patchday
2020-01
Released on
2016/07/12

Description
Whitelist service for Clickjacking Framing Protection in AS ABAP

 

Related note
2863743
CVSS
6.1

Affected system type
Java
Patchday
2020-01
Released on
2020/01/14

Description
[CVE-2020-6305] Cross-Site Scripting (XSS) vulnerability in Rest Adapter of SAP Process Integration

 

Related note
2871877
CVSS
8.3

Affected system type
ABAP
Patchday
2020-01
Released on
2019/12/24

Description
Multiple security vulnerabilities in SAP EAM, add-on for MRO 4.0 by HCL for SAP S/4HANA 1809

 

Related note
2772325
CVSS
5.4

Affected system type
SAP Disclosure Management
Patchday
2020-01
Released on
2020/01/13

Description
[CVE-2020-6303] Improper input validation in SAP Disclosure Management

 

Related note
2843016
CVSS
4.3

Affected system type
ABAP
Patchday
2020-01
Released on
2019/11/12

Description
[CVE-2019-0388] Content spoofing vulnerability in UI5 HTTP Handler

 

Related note
2865348
CVSS
2.7

Affected system type
ABAP
Patchday
2020-01
Released on
2020/01/14

Description
[CVE-2020-6306] Missing Authorization check in SAP Leasing

 

Related note
2165892
CVSS
6.3

Affected system type
ABAP
Patchday
2020-01
Released on
2020/01/14

Description
Missing authorization check in Transaction Manager

 

Related note
2863397
CVSS
4.3

Affected system type
ABAP
Patchday
2020-01
Released on
2020/01/14

Description
[CVE-2020-6307] Missing Authorization Check in Automated Note Search Tool (SAP_BASIS)

 

Related note
2803554
CVSS
5.3

Affected system type
ABAP
Patchday
2019-12
Released on
2019/12/10

Description
[CVE-2019-0399] Potential Information Disclosure in SAP Portfolio and Project Management

 

Related note
2814462
CVSS
5.3

Affected system type
ABAP
Patchday
2019-12
Released on
2019/11/26

Description
Missing Authorization Check in S/4Hana ACR Brazil Option Features

 

Related note
2845780
CVSS
6.7

Affected system type
SAP Adaptive Server...
Patchday
2019-12
Released on
2019/12/10

Description
[CVE-2019-0402] Information Disclosure in SAP Adaptive Server Enterprise

 

Related note
2734675
CVSS
6.3

Affected system type
ABAP
Patchday
2019-12
Released on
2019/12/10

Description
Missing Authorization Check in SAP Cash Management

 

Related note
2701027
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2019-12
Released on
2019/12/10

Description
[CVE-2019-0398] Cross-Site Request Forgery (CSRF) vulnerability in SAP BusinessObjects Business Intelligence Platform (Monitoring application)

 

Related note
2830578
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2019-12
Released on
2019/12/10

Description
[CVE-2019-0395] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad)

 

Related note
2745211
CVSS
5.3

Affected system type
Java
Patchday
2019-12
Released on
2019/12/10

Description
Information Disclosure in PI Axis Adapter

 

Related note
2845183
CVSS
5.3

Affected system type
SAP Enable Now
Patchday
2019-12
Released on
2019/12/10

Description
[CVE-2019-0405] Multiple Security vulnerabilities in SAP Enable Now release 1911

 

Related note
2504979
CVSS
6.4

Affected system type
Java
Patchday
2019-12
Released on
2019/12/10

Description
Upgrade SSL support to TLSv1.2

 

Related note
2817937
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2019-11
Released on
2019/11/12

Description
[CVE-2019-0382] XSS vulnerabilty in SAP Business Objects BI Platform (Web Intelligence)

 

Related note
2393937
CVSS
7.1

Affected system type
ABAP
Patchday
2019-11
Released on
2019/11/12

Description
VMC Authority Check

 

Related note
2819170
CVSS
4.3

Affected system type
ABAP
Patchday
2019-11
Released on
2019/11/12

Description
[CVE-2019-0383] Missing Authorization check in SAP Treasury and Risk Management (Transaction Management)

 

Related note
2816035
CVSS
5.4

Affected system type
ABAP
Patchday
2019-11
Released on
2019/11/12

Description
[CVE-2019-0393] SQL injection vulnerability in SAP Quality Management

 

Related note
2814007
CVSS
7.1

Affected system type
BI/BO platform
Patchday
2019-11
Released on
2019/11/12

Description
[CVE-2019-0396] Missing XML Validation vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)

 

Related note
2814357
CVSS
5.9

Affected system type
Java
Patchday
2019-11
Released on
2019/11/12

Description
[CVE-2019-0389] Privilege escalation in SAP NetWeaver Application Server Java

 

Related note
2840520
CVSS
6.3

Affected system type
ABAP
Patchday
2019-11
Released on
2019/11/12

Description
[CVE-2019-0386] - Missing authorization check in ERP Sales and SAP S/4HANA sales (SD-SLS)

 

Related note
2842034
CVSS
5.0

Affected system type
SAP Data Hub
Patchday
2019-11
Released on
2019/11/12

Description
[CVE-2019-0390] Information Disclosure in SAP Data Hub

 

Related note
2828981
CVSS
6.3

Affected system type
ABAP
Patchday
2019-11
Released on
2019/11/12

Description
[CVE-2019-0384] Missing Authorization check in SAP Treasury and Risk Management (Transaction Management)

 

Related note
2835226
CVSS
4.3

Affected system type
Java
Patchday
2019-11
Released on
2019/11/12

Description
[CVE-2019-0391] Information Disclosure in SAP NetWeaver Application Server Java (eCATT service)

 

Related note
2833771
CVSS
6.5

Affected system type
SAP Enable Now
Patchday
2019-11
Released on
2019/11/12

Description
[CVE-2019-0385] Cross-Site Scripting (XSS) vulnerability in SAP Enable Now

 

Related note
2839864
CVSS
9.1

Affected system type
Java
Patchday
2019-11
Released on
2019/11/12

Description
Update 2 to Security Note 2808158: [CVE-2019-0330] OS Command Injection vulnerability in SAP Diagnostics Agent

 

Related note
962319
CVSS
5.3

Affected system type
Java
Patchday
2019-05
Released on
2006/07/07

Description
Detailed error messages with stack trace in Web Dynpro

 

Related note
2494184
CVSS
6.3

Affected system type
Sybase platform
Patchday
2017-08
Released on
2017/08/08

Description
Cross-Site Request Forgery (CSRF) vulnerability in multiple SAP Sybase products

 

Related note
2129892
CVSS
9.0

Affected system type
HCM
Patchday
2015-04
Released on
2015/03/10

Description
Potential Buffer overflow in PA-PAO

 

 
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2024 by SecurityBridge GmbH

v33.0