Security Advisories  

We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.

The user interface, is designed to be as intuitive as possible but we'd love to hear your feedback and opinions.
We hope you like it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 277 and the highest CVSS score is 10.0.

 

 Severity
SAP© Security advisories 277
 System Types
Affected SAP© system types

 

Related note
2963592
CVSS
5.4

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27601] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java (Applications based on HTMLB for Java)

 

Related note
3036436
CVSS
6.5

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27604] Potential XXE Vulnerability in SAP Process Integration (ESR Java Mappings)

 

Related note
2818965
CVSS
4.6

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
Clickjacking vulnerability in Runtime Workbench of SAP Process Integration

 

Related note
3017908
CVSS
8.3

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-21482] Information Disclosure in SAP NetWeaver Master Data Management

 

Related note
2911863
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2021-04
Released on
2021/04/13

Description
Information Disclosure in BOE/CMC application

 

Related note
3025054
CVSS
4.3

Affected system type
ABAP
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27605 ] Missing Authorization check in HCM Travel Management Fiori Apps V2

 

Related note
3035472
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-04
Released on
2021/03/18

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3027937
CVSS
6.5

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27598] Improper Access Control in SAP NetWeaver AS for Java (Customer Usage Provisioning Servlet)

 

Related note
3036679
CVSS
5.3

Affected system type
ABAP
Patchday
2021-04
Released on
2021/04/13

Description
Update 1 to Security Note 1576763: Potential information disclosure relating to usernames

 

Related note
3028729
CVSS
6.5

Affected system type
ABAP
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27603] Denial of Service (DoS) in SAP NetWeaver AS of ABAP

 

Related note
3012277
CVSS
6.5

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27599] Information Disclosure in SAP Process Integration (Integration Builder Framework)

 

Related note
3025637
CVSS
4.3

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-21492] Content spoofing in NetWeaver AS Java HTTP Service

 

Related note
3005802
CVSS
5.4

Affected system type
ABAP
Patchday
2021-04
Released on
2021/03/23

Description
Cross-Site Request Forgery (CSRF) vulnerability in S/4HANA Finance for advanced payment management

 

Related note
3001824
CVSS
7.4

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-21485] Information Disclosure in SAP NetWeaver AS for Java (Telnet Commands)

 

Related note
3030948
CVSS
4.6

Affected system type
SAP Solution Manager...
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27609] Missing Authorization check in SAP Focused RUN

 

Related note
3024414
CVSS
6.4

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27600 ] Cross-Site Scripting (XSS) vulnerability in SAP Manufacturing Execution (System Rules)

 

Related note
3039649
CVSS
7.5

Affected system type
SAP GUI / Frontend
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27608] Unquoted Search Path in SAPSetup

 

Related note
3017823
CVSS
8.2

Affected system type
SAP Solution Manager
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-21483] Information Disclosure in SAP Solution Manager

 

Related note
3040210
CVSS
9.9

Affected system type
SAP Commerce / SAP...
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27602] Remote Code Execution vulnerability in Source Rules of SAP Commerce

 

Related note
2983436
CVSS
6.5

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21488] Insecure deserialisation in SAP NetWeaver Knowledge Management

 

Related note
2475705
CVSS
6.3

Affected system type
ABAP
Patchday
2021-03
Released on
2021/02/23

Description
Switchable Authorization checks for RFC in In House Cash

 

Related note
2976947
CVSS
4.7

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21491] Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on Web Dynpro Java)

 

Related note
2977001
CVSS
4.7

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on HTMLB for Java)

 

Related note
3027767
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-27592] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3022622
CVSS
9.9

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence

 

Related note
3017378
CVSS
7.7

Affected system type
SAP HANA Platform
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21484] Possible authentication bypass in SAP HANA LDAP scenarios

 

Related note
3027758
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-03
Released on
2021/03/09

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3023778
CVSS
6.8

Affected system type
ABAP
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21487] Missing Authorization Check in Payment Engine

 

Related note
3007888
CVSS
6.8

Affected system type
ABAP
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21486] Missing Authorization check in SAP Enterprise Financial Services( Bank Customer Accounts )

 

Related note
2978151
CVSS
4.7

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
Reverse tabnabbing issue in Unified Rendering based frameworks in NetWeaver Application Server Java

 

Related note
3022422
CVSS
9.6

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21481] Missing Authorization Check in SAP NetWeaver AS JAVA (MigrationService)

 

Related note
2990992
CVSS
5.4

Affected system type
ABAP
Patchday
2021-02
Released on
2021/02/09

Description
Missing Authorization Checks in the Monitor Data and My Data Collections Apps

 

Related note
3000897
CVSS
4.0

Affected system type
Java
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21475] Directory Traversal vulnerability in SAP NetWeaver Master Data Management 7.1

 

Related note
2994289
CVSS
4.1

Affected system type
ABAP
Patchday
2021-02
Released on
2021/02/09

Description
Reverse Tabnabbing vulnerability within SAP CRM WebClient UI

 

Related note
2835240
CVSS
5.4

Affected system type
Java
Patchday
2021-02
Released on
2021/02/09

Description
Clickjacking vulnerability in Cloud Integration Content of SAP Process Integration

 

Related note
3014121
CVSS
9.9

Affected system type
SAP Commerce Cloud
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21477] Remote Code Execution vulnerability in SAP Commerce

 

Related note
2818963
CVSS
0.0

Affected system type
Java
Patchday
2021-02
Released on
2021/02/09

Description
Clickjacking vulnerability in Adapter Runtime of SAP Process Integration

 

Related note
2935791
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21444] Clickjacking vulnerability in SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad)

 

Related note
2998173
CVSS
6.3

Affected system type
SAP Netweaver
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21472] Server password not set during installation of SAP NetWeaver Master Data Management 7.1

 

Related note
2992154
CVSS
4.1

Affected system type
SAP HANA Platform
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21474] SAML Assertion Signature MD5 Digest Algorithm Vulnerability in SAP HANA Database

 

Related note
2973428
CVSS
4.7

Affected system type
Kernal
Patchday
2021-02
Released on
2021/02/09

Description
Reverse Tabnabbing vulnerability within SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML)

 

Related note
2974582
CVSS
4.7

Affected system type
ABAP
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21478] Reverse Tabnabbing vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP)

 

Related note
3000291
CVSS
3.6

Affected system type
Analysis for Office
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21470] XML External Entity vulnerability in SAP EPM add-in

 

Related note
3000306
CVSS
7.5

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21446] Denial of service (DOS) in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
2743329
CVSS
6.3

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
Switchable authorization checks for RFC module in In-House-Cash.

 

Related note
3001373
CVSS
8.9

Affected system type
Cloud Foundry
Patchday
2021-01
Released on
2020/12/22

Description
Information Disclosure in Central Order

 

Related note
2665387
CVSS
5.5

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
Cross-Site Request Forgery (CSRF) vulnerability in Cash Management

 

Related note
3008422
CVSS
4.3

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21467] Missing Authorization check in SAP Banking Services (Generic Market Data)

 

Related note
2993032
CVSS
5.3

Affected system type
Java
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21469] Information Disclosure in SAP NetWeaver Master Data Management

 

Related note
3002617
CVSS
4.3

Affected system type
Visual Enterprise
Patchday
2021-01
Released on
2021/01/12

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
2992269
CVSS
5.3

Affected system type
SAP GUI / Frontend
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21448] Information Disclosure in SAP GUI for Windows

 

Related note
2999854
CVSS
9.9

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21466] Code Injection in SAP Business Warehouse and SAP BW/4HANA

 

Related note
2984034
CVSS
5.4

Affected system type
SAP Commerce Cloud
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21445] Header Manipulation vulnerability in SAP Commerce Cloud

 

Related note
2965154
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21447] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)

 

Related note
2986980
CVSS
9.9

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21465] Multiple vulnerabilities in SAP Business Warehouse (Database Interface)

 

Related note
2989719
CVSS
6.3

Affected system type
ABAP
Patchday
2020-12
Released on
2020/11/24

Description
Missing Authorization check in S/4HANA (Central Finance)

 

Related note
2983367
CVSS
9.1

Affected system type
ABAP
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26838] Code Injection vulnerability in SAP Business Warehouse (Master Data Management) and SAP BW4HANA

 

Related note
2974774
CVSS
10.0

Affected system type
Java
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26829] Missing Authentication Check in SAP NetWeaver AS JAVA (P2P Cluster Communication)

 

Related note
2971163
CVSS
5.4

Affected system type
Java
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26816] Missing Encryption in SAP NetWeaver AS Java (Key Storage Service)

 

Related note
2996479
CVSS
5.3

Affected system type
ABAP
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26835] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP

 

Related note
2983204
CVSS
8.5

Affected system type
SAP Solution Manager
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26837] Multiple Vulnerabilities in SAP Solution Manager 7.2 (User Experience Monitoring)

 

Related note
2974330
CVSS
6.5

Affected system type
Java
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26826] Unrestricted File Upload vulnerability in SAP NetWeaver Application Server for Java (Process Integration Monitoring)

 

Related note
2978768
CVSS
4.2

Affected system type
HANA Platform
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26834 ] Improper authentication in SAP HANA database

 

Related note
2993132
CVSS
7.6

Affected system type
ABAP
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26832] Missing Authorization check in SAP NetWeaver AS ABAP and SAP S4 HANA (SAP Landscape Transformation)

 

Related note
2989075
CVSS
9.6

Affected system type
BI/BO platform
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26831] Missing XML Validation in SAP BusinessObjects Business Intelligence Platform (Crystal Report)

 

Related note
2938650
CVSS
3.4

Affected system type
ABAP
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26836] Open Redirect in SAP Solution Manager (Trace Analysis)

 

Related note
2971180
CVSS
5.4

Affected system type
SAP Disclosure Management
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26828] Formula Injection in SAP Disclosure Management

 

Related note
2264508
CVSS
5.4

Affected system type
ABAP
Patchday
2020-11
Released on
2020/10/27

Description
SQL Injection in SAF-T Portugal

 

Related note
2952084
CVSS
4.9

Affected system type
Java
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26814] Information Disclosure in SAP Process Integration (PGP Module – Business-to-Business Add On)

 

Related note
2979062
CVSS
9.1

Affected system type
Java
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26820] Privilege escalation in SAP NetWeaver Application Server for Java (UDDI Server)

 

Related note
2973735
CVSS
9.1

Affected system type
ABAP
Patchday
2020-11
Released on
2020/11/11

Description
[CVE-2020-26808] Code Injection in SAP AS ABAP and S/4 HANA (DMIS)

 

Related note
2982840
CVSS
9.8

Affected system type
SAP Data Services
Patchday
2020-11
Released on
2020/11/10

Description
Multiple Vulnerabilities in SAP Data Services

 

Related note
2975170
CVSS
7.5

Affected system type
SAP Commerce Cloud
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26810] Multiple Vulnerabilities in SAP Commerce Cloud (Accelerator Payment Mock)

 

Related note
2985094
CVSS
4.3

Affected system type
Visual Enterprise
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26817] Improper input validation in Visual Enterprise Viewer

 

Related note
2944188
CVSS
4.3

Affected system type
ABAP
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-6316] Missing Authorization Check in SAP ERP and SAP S/4 HANA

 

Related note
2319577
CVSS
5.4

Affected system type
ABAP
Patchday
2020-11
Released on
2020/10/27

Description
SQL Injection in SAF-T Portugal

 

Related note
2984627
CVSS
8.6

Affected system type
ABAP
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26815] Security Vulnerabilities in SAP Fiori Launchpad (NewsTile Application)

 

Related note
2947891
CVSS
3.0

Affected system type
ABAP
Patchday
2020-11
Released on
2020/11/10

Description
Missing Authorization check in Disbursement Read API used in Read Disbursement Webservice

 

Related note
2971954
CVSS
6.5

Affected system type
ABAP
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26818] Multiple vulnerabilities in SAP NetWeaver AS ABAP (Web Dynpro)

 

Related note
2971112
CVSS
4.4

Affected system type
SAP ERP Client for E-Bilanz
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26807] Incorrect Default Permissions in SAP ERP Client for E-Bilanz 1.0

 

Related note
2975189
CVSS
7.5

Affected system type
SAP Commerce Cloud
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26809] Information Disclosure in SAP Commerce Cloud

 

Related note
2985866
CVSS
10.0

Affected system type
Java
Patchday
2020-11
Released on
2020/11/10

Description
[Multiple CVE IDs] Missing Authentication Check in SAP Solution Manager (JAVA stack)

 

Related note
2824209
CVSS
5.4

Affected system type
Java
Patchday
2020-11
Released on
2020/11/10

Description
Clickjacking vulnerability in SAP Process Integration (Integration Builder Framework)

 

Related note
2956398
CVSS
6.1

Affected system type
Java
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6319] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java

 

Related note
2943844
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6308] Server-Side Request Forgery vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Services)

 

Related note
2606194
CVSS
4.4

Affected system type
ABAP
Patchday
2020-10
Released on
2020/09/09

Description
Cross-Site Scripting (XSS) vulnerability in CRM Interaction Center

 

Related note
2965315
CVSS
4.7

Affected system type
Java
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6365] Reverse Tabnabbing vulnerability in SAP NetWeaver AS Java Start Page

 

Related note
2917381
CVSS
5.4

Affected system type
SAP Commerce Cloud
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6272] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Cloud

 

Related note
2972661
CVSS
8.2

Affected system type
Java
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6367] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Composite Application Framework

 

Related note
2883638
CVSS
6.5

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
Information Disclosure in Supplier Relationship Management

 

Related note
2955963
CVSS
4.3

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
Cross-Site Request Forgery (CSRF) in SAP Marketing

 

Related note
2960825
CVSS
5.4

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6368] Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation

 

Related note
2973100
CVSS
3.6

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
Missing Authorization check in Manage Substitutions - Products and Manage Exclusions - Products

 

Related note
2965287
CVSS
3.7

Affected system type
SAP Commerce Cloud
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6363] Insufficient Session Expiration in SAP Commerce Cloud

 

Related note
2969828
CVSS
10.0

Affected system type
Solution Manager
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6364] OS Command Injection Vulnerability in CA Introscope Enterprise Manager (Affected Products: SAP Solution Manager and SAP Focused Run)

 

Related note
2873099
CVSS
5.4

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
Missing Authorization check in EHS Task Definition attachments

 

Related note
2945581
CVSS
4.7

Affected system type
SAP CRM UI
Patchday
2020-10
Released on
2020/09/22

Description
Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI

 

Related note
2960329
CVSS
4.4

Affected system type
SAP Enterprise Portal...
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6323] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (Fiori Framework Page)

 

Related note
2953212
CVSS
4.3

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6362] Incorrect Authorization in SAP Banking Services

 

Related note
2973497
CVSS
5.7

Affected system type
SAP 3D Visual Eneprise
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6315] Multiple Vulnerabilities in SAP 3D Visual Enterprise Viewer

 

Related note
2963137
CVSS
4.3

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6371] Information disclosure in SAP NetWeaver AS ABAP via the POWL Test Feeder endpoint

 

Related note
2971638
CVSS
7.5

Affected system type
SAP Solution Manager...
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6369] Hard-coded Credentials in CA Introscope Enterprise Manager (Affected products: SAP Solution Manager and SAP Focused Run)

 

Related note
2969457
CVSS
7.6

Affected system type
Java
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6366] Missing XML Validation in SAP NetWeaver (Compare Systems)

 

Related note
2939419
CVSS
4.8

Affected system type
SAP NetWeaver...
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6370] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (DI Design Time Repository)

 

Related note
2531082
CVSS
6.3

Affected system type
ABAP
Patchday
2020-09
Released on
2019/03/12

Description
Switchable Authorization checks for RFC BCA_DIM_LOANS_APPLOG_UPDATE in Loans (FI-CAX-FS)

 

Related note
2930128
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6325] Multiple Vulnerabilities in SAP BusinessObjects Business Intelligence Platform

 

Related note
2924859
CVSS
6.5

Affected system type
ABAP
Patchday
2020-09
Released on
2020/08/25

Description
Missing Authorization check in Discrete Industries and Mill Products

 

Related note
2865229
CVSS
4.8

Affected system type
SAP UI5
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6283] Cross-Site Scripting (XSS) vulnerability in SAP Fiori(Launchpad)

 

Related note
2958563
CVSS
9.1

Affected system type
ABAP
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6318] Code Injection vulnerability in SAP NetWeaver (ABAP Server) and ABAP Platform

 

Related note
2953203
CVSS
2.6

Affected system type
SAP Adaptive Server...
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6317] Information Disclosure in SAP Adaptive Server Enterprise

 

Related note
2953112
CVSS
5.4

Affected system type
Java
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6326] Cross-Site Scripting (XSS) vulnerabilities in SAP NetWeaver AS Java

 

Related note
2951325
CVSS
6.5

Affected system type
ABAP
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6311] Improper Authorization Checks in Banking services from SAP Bank Analyzer and SAP S/4HANA Financial Products

 

Related note
2948239
CVSS
6.1

Affected system type
ABAP
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6324] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Test Application)

 

Related note
2934451
CVSS
6.4

Affected system type
SAP Commerce Cloud
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6302] Session Fixation in SAP Commerce

 

Related note
2960815
CVSS
4.3

Affected system type
SAP 3D Visual Eneprise
Patchday
2020-09
Released on
2020/09/08

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
2961991
CVSS
9.6

Affected system type
SAP Marketing
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6320] Improper Access Control in SAP Marketing (Mobile Channel Servlet)

 

Related note
2921615
CVSS
5.5

Affected system type
BI/BO platform
Patchday
2020-08
Released on
2020/08/11

Description
BI Platform stores SAP BW Authentication Password as clear text

 

Related note
2949196
CVSS
5.4

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6301] Missing Authorization check in SAP ERP (HCM Travel Management)

 

Related note
2948317
CVSS
6.1

Affected system type
SAP Commerce
Patchday
2020-08
Released on
2020/08/11

Description
Vulnerabilities in open source libraries used in SAP Commerce

 

Related note
2928635
CVSS
9.0

Affected system type
Java
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6284] Cross-Site Scripting (XSS) in SAP NetWeaver (Knowledge Management)

 

Related note
2927956
CVSS
8.5

Affected system type
BI/BO platform
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6294] Missing Authentication check in SAP BusinessObjects Business Intelligence Platform

 

Related note
2941315
CVSS
7.5

Affected system type
Java
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6309] Missing Authentication check in SAP NetWeaver AS JAVA

 

Related note
2944988
CVSS
4.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6310] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform

 

Related note
2938162
CVSS
7.3

Affected system type
Java
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6293] Unrestricted File Upload in SAP NetWeaver (Knowledge Management)

 

Related note
2885671
CVSS
4.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6273] Missing Authorization check in SAP S/4 HANA (Fiori UI for General Ledger Accounting)

 

Related note
2754546
CVSS
5.0

Affected system type
Lumira Designer
Patchday
2020-08
Released on
2020/08/11

Description
Potential information disclosure in Lumira Designer

 

Related note
2939685
CVSS
8.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6298] Missing Authorization check in SAP Banking Services (Generic Market Data)

 

Related note
2756551
CVSS
6.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
Missing Authorization check in TSW Supply Chain Visualization

 

Related note
2925827
CVSS
4.8

Affected system type
BI/BO platform
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6300] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(Central Management Console)

 

Related note
2941667
CVSS
8.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6296] Code Injection Vulnerability in SAP NetWeaver (ABAP) and ABAP Platform

 

Related note
2941332
CVSS
7.0

Affected system type
SAP Adaptive Server...
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6295] Information Disclosure in SAP Adaptive Server Enterprise

 

Related note
2941510
CVSS
4.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6299] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform

 

Related note
2940823
CVSS
6.3

Affected system type
SAP Data Hub
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6297] Information Disclosure in SAP Data Intelligence

 

Related note
2593479
CVSS
3.9

Affected system type
Java
Patchday
2020-08
Released on
2018/06/15

Description
Checking server certificates and host name of managed systems

 

Related note
2941170
CVSS
6.1

Affected system type
SAPGUI / Frontend
Patchday
2020-08
Released on
2020/08/11

Description
Cross-Site Scripting (XSS) vulnerabilities in modified jQuery bundled with SAPUI5

 

Related note
2896025
CVSS
5.8

Affected system type
Java
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6282] Server-Side Request Forgery in SAP NetWeaver AS JAVA (IIOP service)

 

Related note
2927373
CVSS
2.7

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6280] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform

 

Related note
2537961
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Switchable Authorization checks for RFC in MM-PUR-GF

 

Related note
2603398
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Missing authorization check in Allocation Management

 

Related note
2486446
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Missing Authorization check in Pricat Inbound and Pricat Outbound

 

Related note
2934135
CVSS
10.0

Affected system type
Java
Exploit available
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6287] Multiple Vulnerabilities in SAP NetWeaver AS JAVA (LM Configuration Wizard)

 

Related note
2541823
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/06/09

Description
Switchable authorization checks for RFC in SAP CRM (external billing)

 

Related note
2091403
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2015/08/11

Description
Directory traversal in BC-MID-ICF

 

Related note
2847817
CVSS
4.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Missing Authorization check in Travel Management

 

Related note
2932473
CVSS
7.7

Affected system type
Java
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6285] Information Disclosure in SAP NetWeaver (XMLToolkit for Java)

 

Related note
2917743
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6281] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(BI Launch pad)

 

Related note
2912708
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6278] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC)

 

Related note
2874738
CVSS
3.8

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Missing Authorization Check in S4 ACR Brazil Option

 

Related note
2758000
CVSS
6.3

Affected system type
SAP Disclosure Management
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6267] Multiple vulnerabilities in SAP Disclosure Management

 

Related note
2849967
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6276] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(Bipodata)

 

Related note
2916562
CVSS
6.5

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6270] Missing Authorization check in SAP Netweaver AS ABAP (Banking Services)

 

Related note
2933282
CVSS
8.1

Affected system type
SAP Success Factors
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6279] Missing Authorization Check in SAP SuccessFactors Recruiting

 

Related note
2912939
CVSS
7.6

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6275] Server Side Request Forgery vulnerability in SAP NetWeaver AS ABAP

 

Related note
2878568
CVSS
6.9

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6263] Authentication Bypass in Standalone Clients connecting to SAP NetWeaver AS Java via P4 Protocol

 

Related note
2931391
CVSS
8.2

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6271] Missing XML Validation in SAP Solution Manager (Problem Context Manager)

 

Related note
2928570
CVSS
9.8

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
Ghostcat' Apache Tomcat AJP Vulnerability in SAP Liquidity Management for Banking

 

Related note
2923035
CVSS
4.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI

 

Related note
2906996
CVSS
5.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6268] Missing authorization check in SAP ERP (Statutory Reporting for Insurance Companies)

 

Related note
2906366
CVSS
8.6

Affected system type
SAP Cloud Commerce
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6264] Information Disclosure in SAP Commerce

 

Related note
2905836
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6269] Information Disclosure in SAP Business Objects Business Intelligence Platform

 

Related note
2915126
CVSS
6.5

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6260] Incomplete XML Validation in SAP Solution Manager (Trace Analysis)

 

Related note
2911704
CVSS
5.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA

 

Related note
2911687
CVSS
5.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA

 

Related note
2911267
CVSS
4.3

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
Update 1 to Security Note 2752614 - [CVE-2019-0319] Content Injection Vulnerability in SAP Gateway

 

Related note
2908382
CVSS
4.4

Affected system type
SAP Business One
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6239] Information Disclosure in SAP Business One (Backup Service)

 

Related note
2540180
CVSS
6.3

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
Switchable Authorization checks for RFC in Environment, Health & Safety

 

Related note
2918924
CVSS
9.8

Affected system type
SAP Cloud Commerce
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6265] Use of Hard-coded Credentials in SAP Commerce and SAP Commerce Datahub

 

Related note
2918762
CVSS
6.5

Affected system type
Adobe LiveCycle Designer
Patchday
2020-06
Released on
2020/06/09

Description
Multiple vulnerabilities in Adobe LiveCycle Designer 11.0

 

Related note
2878935
CVSS
6.1

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6246] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP ( Business Server Pages Test Application SBSPEXT_TABLE)

 

Related note
2747062
CVSS
5.0

Affected system type
ABAP
Patchday
2020-05
Released on
2020/05/12

Description
This note has been re-released without changes. - Cross-Site Request Forgery (CSRF) vulnerability in SAP Web Dynpro ABAP

 

Related note
2913293
CVSS
6.1

Affected system type
SAP Enterprise Threat...
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6254] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Threat Detection