Security Advisories  

We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.

The user interface, is designed to be as intuitive as possible but we'd love to hear your feedback and opinions.
We hope you like it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 667 and the highest CVSS score is 10.0.

 

 Severity
SAP© Security advisories 667
 System Types
Affected SAP© system types

 

Related note
3328495
CVSS
9.8

Affected system type
Reprise License Manager
Patchday
2023-05
Released on
2023/05/09

Description
Multiple vulnerabilities associated with Reprise License Manager 14.2 component used with SAP 3D Visual Enterprise License Manager

 

Related note
3315979
CVSS
5.4

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-29188] Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI

 

Related note
3312892
CVSS
5.4

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-31407] Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation

 

Related note
3315971
CVSS
6.1

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)

 

Related note
3309935
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30741] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform

 

Related note
3302595
CVSS
3.7

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-28764] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform

 

Related note
3313484
CVSS
6.3

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30740] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform

 

Related note
3300624
CVSS
7.5

Affected system type
SAP PowerDesigner
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-32111] Memory Corruption vulnerability in SAP PowerDesigner (Proxy)

 

Related note
3323415
CVSS
8.2

Affected system type
SAP Integrated...
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-29080] Privilege escalation vulnerability in SAP IBP, add-in for Microsoft Excel

 

Related note
3321309
CVSS
7.5

Affected system type
SAP Commerce
Patchday
2023-05
Released on
2023/05/09

Description
Information Disclosure vulnerability in SAP Commerce (Backoffice)

 

Related note
3038911
CVSS
5.0

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-31404] Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Service)

 

Related note
3320467
CVSS
7.5

Affected system type
SAP GUI / Frontend
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-32113] Information Disclosure vulnerability in SAP GUI for Windows

 

Related note
3307833
CVSS
9.1

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-28762] Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Console)

 

Related note
3319400
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-31406] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform

 

Related note
3317453
CVSS
8.2

Affected system type
Java
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30744] Improper access control during application start-up in SAP AS NetWeaver JAVA

 

Related note
3320145
CVSS
7.5

Affected system type
SAP Commerce
Patchday
2023-05
Released on
2023/05/09

Description
Denial of service (DOS) in SAP Commerce

 

Related note
2335198
CVSS
2.8

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-32112] Missing Authorization Check in Vendor Master Hierarchy

 

Related note
3326210
CVSS
7.1

Affected system type
ABAP
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-30743] Improper Neutralization of Input in SAPUI5

 

Related note
3301457
CVSS
4.3

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-1903] Missing Authorization check in SAP HCM Fiori App My Forms (Fiori 2.0)

 

Related note
3305369
CVSS
10.0

Affected system type
Java
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-27497] Multiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge and EventLogServiceCollector)

 

Related note
3117978
CVSS
3.1

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29111] Information Disclosure vulnerability in SAP Application Interface Framework (ODATA service)

 

Related note
3287784
CVSS
5.3

Affected system type
Java
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-24527] Improper Access Control in SAP NetWeaver AS Java for Deploy Service

 

Related note
3303060
CVSS
5.3

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29185] Denial of Service (DOS) in SAP NetWeaver AS for ABAP (Business Server Pages)

 

Related note
3269352
CVSS
5.4

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29189] HTTP Verb Tampering vulnerability in SAP CRM (WebClient UI)

 

Related note
3309056
CVSS
6.0

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-27897] Code Injection vulnerability in SAP CRM

 

Related note
3298961
CVSS
9.8

Affected system type
BI/BO platform
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-28765] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management )

 

Related note
3275458
CVSS
6.1

Affected system type
Kernel
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-27499] Cross-Site Scripting (XSS) vulnerability in SAP GUI for HTML

 

Related note
3315312
CVSS
5.0

Affected system type
Kernel
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29108] IP filter vulnerability in ABAP Platform and SAP Web Dispatcher

 

Related note
3114489
CVSS
3.7

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29112] Code Injection vulnerability in SAP Application Interface Framework (Message Monitoring)

 

Related note
3312733
CVSS
6.8

Affected system type
Java
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-26458] Information Disclosure vulnerability in SAP Landscape Management

 

Related note
3316509
CVSS
4.7

Affected system type
SAP Commerce
Patchday
2023-04
Released on
2023/04/11

Description
Remote Code Execution vulnerability in SAP Commerce

 

Related note
3305907
CVSS
8.7

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29186] Directory Traversal vulnerability in SAP NetWeaver ( BI CONT ADD ON)

 

Related note
3115598
CVSS
4.4

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29109] Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard)

 

Related note
3113349
CVSS
3.7

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29110] Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard)

 

Related note
3311624
CVSS
6.7

Affected system type
SAP GUI / Frontend
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-29187] DLL Hijacking vulnerability in SapSetup (Software Installation Program)

 

Related note
3289994
CVSS
6.5

Affected system type
Java
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-28761] Missing Authentication check in SAP NetWeaver Enterprise Portal

 

Related note
3296378
CVSS
6.5

Affected system type
ABAP
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-28763] - Denial of Service in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3245526
CVSS
9.9

Affected system type
BI/BO platform
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-25616] Code Injection vulnerability in SAP Business Objects Business Intelligence Platform (CMC)

 

Related note
3289844
CVSS
6.8

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-25615] SQL Injection vulnerability in SAP ABAP Platform

 

Related note
3296476
CVSS
8.8

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27893] Arbitrary Code Execution in SAP Solution Manager and ABAP managed systems (ST-PI)

 

Related note
3288394
CVSS
5.3

Affected system type
Java
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-24526] Improper Access Control in SAP NetWeaver AS Java (Classload Service)

 

Related note
3274920
CVSS
6.1

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-0021] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver

 

Related note
3287120
CVSS
6.5

Affected system type
BI/BO platform
Patchday
2023-03
Released on
2023/03/14

Description
[Multiple CVEs] Multiple vulnerabilities in the SAP BusinessObjects Business Intelligence platform

 

Related note
3296346
CVSS
7.4

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-26459] Multiple vulnerabilities in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3252433
CVSS
9.9

Affected system type
Java
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-23857] Improper Access Control in SAP NetWeaver AS for Java

 

Related note
3302162
CVSS
9.6

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27500] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3294595
CVSS
9.6

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27269] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3288096
CVSS
5.3

Affected system type
Java
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-26460] Improper Access Control in SAP NetWeaver AS Java (Cache Management Service)

 

Related note
3288480
CVSS
5.3

Affected system type
Java
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27268] Improper Access Control in SAP NetWeaver AS Java (Object Analyzing Service)

 

Related note
3281484
CVSS
6.1

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-26457] Cross-Site Scripting (XSS) vulnerability in SAP Content Server

 

Related note
3296328
CVSS
6.5

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27270] Denial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3284550
CVSS
6.8

Affected system type
Java
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-26461] XML External Entity (XXE) vulnerability in SAP NetWeaver (SAP Enterprise Portal)

 

Related note
3275727
CVSS
7.2

Affected system type
SAP Host Agent
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27498] Memory Corruption vulnerability in SAPOSCOL

 

Related note
3302710
CVSS
6.1

Affected system type
SAP Authenticator for Android
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27895] Information Disclosure vulnerability in SAP Authenticator for Android

 

Related note
3283438
CVSS
9.0

Affected system type
BI/BO platform
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-25617] OS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform (Adaptive Job Server)

 

Related note
3294954
CVSS
8.7

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27501] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
2985905
CVSS
6.5

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24524] Missing Authorization check in SAP S/4 HANA Map Treasury Correspondence Format Data

 

Related note
3270509
CVSS
6.5

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-23855] URL Redirection vulnerability in SAP Solution Manager

 

Related note
3290901
CVSS
6.5

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24528] Missing Authorization Check in SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests)

 

Related note
3287291
CVSS
3.8

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-23854] Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3265846
CVSS
6.5

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-0024] Cross Site Scripting in SAP Solution Manager (BSP Application)

 

Related note
3256787
CVSS
8.4

Affected system type
BI/BO platform
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24530] Unrestricted Upload of File in SAP BusinessObjects Business Intelligence Platform (CMC)

 

Related note
3285757
CVSS
8.8

Affected system type
SAP Host Agent
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24523] Privilege Escalation vulnerability in SAP Host Agent (Start Service)

 

Related note
3271227
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-23853] URL Redirection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
3293786
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-23858] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3269118
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24522] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Framework)

 

Related note
3269151
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24521] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Framework)

 

Related note
3267442
CVSS
6.5

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-0025] Cross Site Scripting in SAP Solution Manager (BSP Application)

 

Related note
3282663
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24529] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (Business Server Pages application)

 

Related note
3268959
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[Multiple CVEs] Multiple vulnerabilities in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3281724
CVSS
6.5

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-0019] Missing Authorization check in SAP GRC (Process Control)

 

Related note
3266751
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-23852] Cross-Site Scripting (XSS) vulnerability in SAP Solution Manager 7.2

 

Related note
3275841
CVSS
5.4

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-23851] Unrestricted File Upload in SAP Business Planning and Consolidation

 

Related note
3263135
CVSS
8.5

Affected system type
BI/BO platform
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-0020] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence platform

 

Related note
3263863
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-23856] Cross-Site Scripting (XSS) vulnerability in Web Intelligence Interface

 

Related note
3274585
CVSS
6.1

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-25614] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Framework)

 

Related note
2788178
CVSS
4.3

Affected system type
ABAP
Patchday
2023-02
Released on
2023/02/14

Description
[CVE-2023-24525] Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI

 

Related note
3276120
CVSS
6.4

Affected system type
SAP Host Agent
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0012] Local Privilege Escalation in SAP Host Agent (Windows)

 

Related note
3089413
CVSS
9.0

Affected system type
Kernel / ABAP
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0014] Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3150704
CVSS
4.5

Affected system type
ABAP
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0023] Information Disclosure in SAP Bank Account Management (Manage Banks)

 

Related note
3266006
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0018] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)

 

Related note
3262810
CVSS
9.9

Affected system type
BI/BO platform
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0022] Code Injection vulnerability in SAP BusinessObjects Business Intelligence platform (Analysis edition for OLAP)

 

Related note
3275391
CVSS
9.9

Affected system type
SAP Business Planning...
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0016] SQL Injection vulnerability in SAP Business Planning and Consolidation MS

 

Related note
3283283
CVSS
6.1

Affected system type
ABAP
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0013] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3251447
CVSS
4.6

Affected system type
BI/BO platform
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0015] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence (Web Intelligence)

 

Related note
3268093
CVSS
9.4

Affected system type
Java
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0017] Improper access control in SAP NetWeaver AS for Java

 

Related note
3271313
CVSS
6.1

Affected system type
ABAP
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41275] Offener Redirect in SAP Solutions Manager (Enterprise Search)

 

Related note
3248255
CVSS
8.0

Affected system type
SAP Commerce
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41266] Cross-Site Scripting (XSS) vulnerability in SAP Commerce

 

Related note
3268172
CVSS
8.8

Affected system type
ABAP
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41264] Code Injection vulnerability in SAP BASIS

 

Related note
3262544
CVSS
6.1

Affected system type
Java
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41262] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for Java (Http Provider Service)

 

Related note
3258950
CVSS
6.1

Affected system type
ABAP
Patchday
2022-12
Released on
2022/12/13

Description
Update 1 to Security Note 2872782 - [CVE-2020-6215] URL Redirection vulnerability in SAP NetWeaver AS ABAP (BSP Test Application)

 

Related note
3273480
CVSS
9.9

Affected system type
Java
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41272] Improper access control in SAP NetWeaver AS Java (User Defined Search)

 

Related note
3271091
CVSS
8.5

Affected system type
ABAP
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41268] Privilege escalation vulnerability in SAP Business Planning and Consolidation

 

Related note
3239475
CVSS
9.9

Affected system type
BI/BO platform
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41267] Server-Side Request Forgery vulnerability in SAP BusinessObjects Business Intelligence Platform

 

Related note
3267780
CVSS
9.4

Affected system type
Java
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41271] Improper access control in SAP NetWeaver AS Java (Messaging System)

 

Related note
3271523
CVSS
9.8

Affected system type
SAP Commerce
Patchday
2022-12
Released on
2022/12/13

Description
Remote Code Execution vulnerability associated with Apache Commons Text in SAP Commerce

 

Related note
3265173
CVSS
6.0

Affected system type
Java
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41261] Improper Access Control in SAP Solution Manager (Diagnostic Agent)

 

Related note
3270399
CVSS
4.3

Affected system type
Java
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41273] URL Redirection vulnerability in SAP Sourcing and SAP Contract Lifecycle Management

 

Related note
3266846
CVSS
6.5

Affected system type
SAP Disclosure Management
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41274] Missing Authorization Checks in SAP Disclosure Management

 

Related note
3249648
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41263] Missing authentication check vulnerability in SAP Business Objects Business Intelligence Platform (Web intelligence)

 

Related note
3238042
CVSS
6.1

Affected system type
Java
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41207] URL Redirection vulnerability in SAP Biller Direct

 

Related note
3256571
CVSS
8.7

Affected system type
ABAP
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41214] Multiple vulnerabilities in SAP NetWeaver Application Server ABAP and ABAP Platform

 

Related note
3218159
CVSS
6.1

Affected system type
SAP UI5 SAP Fiori
Patchday
2022-11
Released on
2022/11/08

Description
Insufficient Session Expiration in Central Fiori Launchpad

 

Related note
3251202
CVSS
4.7

Affected system type
ABAP
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform

 

Related note
3249990
CVSS
9.8

Affected system type
ABAP, Java
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2021-20223] Multiple Vulnerabilities in SQlite bundled with SAPUI5

 

Related note
3229987
CVSS
6.5

Affected system type
Sybase platform
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41259] Denial of service (DOS) in SAP SQL Anywhere

 

Related note
3237251
CVSS
5.5

Affected system type
SAP GUI
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41205] Code injection vulnerability in SAP GUI for Windows

 

Related note
3260708
CVSS
6.5

Affected system type
SAP Financial Consolidation
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41258] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation

 

Related note
3243924
CVSS
9.9

Affected system type
BI/BO platform
Exploit available
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41203] Insecure Deserialization of Untrusted Data in SAP BusinessObjects Business Intelligence Platform (Central Management Console and BI Launchpad)

 

Related note
3263436
CVSS
7.0

Affected system type
SAP 3D Visual Enterprise
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41211] Arbitrary Code Execution vulnerability in SAP 3D Visual Enterprise Author and SAP 3D Visual Enterprise Viewer

 

Related note
3229132
CVSS
8.2

Affected system type
BI/BO platform
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-39013] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Program Objects)

 

Related note
3229425
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-41206] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform / Analysis for OLAP

 

Related note
3239293
CVSS
7.7

Affected system type
BI/BO platform
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-39015] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform(AdminTools/ Query Builder)

 

Related note
3245929
CVSS
7.0

Affected system type
SAP 3D Visual Enterprise
Patchday
2022-10
Released on
2022/10/11

Description
[Multiple CVEs] Multiple vulnerabilities in SAP 3D Visual Enterprise Author

 

Related note
3248970
CVSS
4.9

Affected system type
SAP Customer Data Cloud
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-41209] Information Disclosure Vulnerability in SAP Customer Data Cloud (Gigya)

 

Related note
3233226
CVSS
6.8

Affected system type
BI/BO platform
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-35296] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Version Management System)

 

Related note
3202523
CVSS
6.1

Affected system type
SAP Commerce
Patchday
2022-10
Released on
2022/10/11

Description
Cross-Site Scripting (XSS) vulnerability in SAP Commerce

 

Related note
3234755
CVSS
4.3

Affected system type
ABAP
Patchday
2022-10
Released on
2022/10/11

Description
Information Disclosure vulnerability in Master Data Governance

 

Related note
3049899
CVSS
6.5

Affected system type
SAP Enable Now
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-35297] Stored Cross-Site Scripting (XSS) vulnerability in SAP Enable Now

 

Related note
3248384
CVSS
4.9

Affected system type
SAP Customer Data Cloud
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-41210] Information Disclosure Vulnerability in SAP Customer Data Cloud (Gigya)

 

Related note
3167342
CVSS
4.8

Affected system type
BI/BO platform
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-35226] Cross-Site Scripting (XSS) vulnerability in Data Services Management Console

 

Related note
3245928
CVSS
7.0

Affected system type
SAP 3D Visual Enterprise
Patchday
2022-10
Released on
2022/10/11

Description
[Multiple CVEs] Multiple vulnerabilities in SAP 3D Visual Enterprise Viewer

 

Related note
3242933
CVSS
9.9

Affected system type
Java
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-39802] File path traversal vulnerability in SAP Manufacturing Execution

 

Related note
2495712
CVSS
6.5

Affected system type
ABAP
Patchday
2022-10
Released on
2022/10/11

Description
Missing authorization check in SAP Automotive Solutions

 

Related note
3211161
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-39800] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI LaunchPad)

 

Related note
3232021
CVSS
8.1

Affected system type
Sybase platform
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-35299] Buffer Overflow in SAP SQL Anywhere and SAP IQ

 

Related note
3159736
CVSS
6.7

Affected system type
SAP Host Agent
Patchday
2022-09
Released on
2022/09/13

Description
[CVE-2022-35295] Privilege Escalation Vulnerability in SAPOSCOL on Unix

 

Related note
3219164
CVSS
6.1

Affected system type
Java
Patchday
2022-09
Released on
2022/09/13

Description
[CVE-2022-35298] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC)

 

Related note
3218177
CVSS
5.4

Affected system type
ABAP
Patchday
2022-09
Released on
2022/09/13

Description
[CVE-2022-35294] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP

 

Related note
3229820
CVSS
6.1

Affected system type
ABAP
Patchday
2022-09
Released on
2022/09/13

Description
[CVE-2022-39799] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad)

 

Related note
3223392
CVSS
7.8

Affected system type
SAP Business One
Patchday
2022-09
Released on
2022/09/13

Description
[CVE-2022-35292] Windows Unquoted Service Path issue in SAP Business One

 

Related note
3217303
CVSS
7.7

Affected system type
BI/BO platform
Patchday
2022-09
Released on
2022/09/13

Description
[CVE-2022-39014] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (CMC)

 

Related note
2634023
CVSS
6.3

Affected system type
ABAP
Patchday
2022-09
Released on
2022/09/13

Description
Missing authorization check in Consumption of CDS Views (or) OData Services in QM-QN

 

Related note
3198137
CVSS
4.7

Affected system type
ABAP
Patchday
2022-09
Released on
2022/09/13

Description
Update 1 to Security Note 3165333 - [CVE-2022-28215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform

 

Related note
3126968
CVSS
4.3

Affected system type
ABAP
Patchday
2022-09
Released on
2022/09/13

Description
Information Disclosure vulnerability in SAP CRM WebClient

 

Related note
3237075
CVSS
7.1

Affected system type
ABAP
Patchday
2022-09
Released on
2022/09/13

Description
[CVE-2022-39801] Insufficient Firefighter Session Expiration in SAP GRC Access Control Emergency Access Management

 

Related note
3216653
CVSS
5.3

Affected system type
SAP Authenticator for Android
Patchday
2022-08
Released on
2022/08/09

Description
[CVE-2022-35290] Information Disclosure in SAP Authenticator for Android

 

Related note
3213141
CVSS
7.3

Affected system type
SAP Landscape...
Patchday
2022-08
Released on
2022/07/26

Description
Information Disclosure in SAP Landscape Management

 

Related note
3213507
CVSS
5.2

Affected system type
BI/BO platform
Patchday
2022-08
Released on
2022/08/09

Description
[CVE-2022-31596] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Monitoring DB)

 

Related note
3210823
CVSS
8.2

Affected system type
BI/BO platform
Patchday
2022-08
Released on
2022/08/09

Description
[CVE-2022-32245] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Open Document)

 

Related note
3213524
CVSS
5.2

Affected system type
BI/BO platform
Patchday
2022-08
Released on
2022/08/09

Description
[CVE-2022-32244] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Commentary DB)

 

Related note
2522794
CVSS
6.3

Affected system type
ABAP
Patchday
2022-08
Released on
2022/08/09

Description
Missing Authorization check in Portugal Digital Signature

 

Related note
3210566
CVSS
4.2

Affected system type
SAP Enable Now
Patchday
2022-08
Released on
2022/08/09

Description
[CVE-2022-35293] Missing authorization check in SAP Enable Now Manager

 

Related note
3156484
CVSS
6.5

Affected system type
SAP GUI / Frontend
Patchday
2022-08
Released on
2022/08/09

Description
Information Disclosure vulnerability in SAP Business Client

 

Related note
3208819
CVSS
6.1

Affected system type
Java
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35170] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3207902
CVSS
6.1

Affected system type
Java
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35172] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3208880
CVSS
6.1

Affected system type
Java
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35225] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3150454
CVSS
4.9

Affected system type
ABAP
Patchday
2022-07
Released on
2022/07/12

Description
Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform

 

Related note
3221288
CVSS
8.3

Affected system type
BI/BO platform
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35228] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)

 

Related note
3157613
CVSS
7.5

Affected system type
SAP Business One
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-28771] Missing Authentication check in SAP Business One (License service API)

 

Related note
3210779
CVSS
6.1

Affected system type
Java
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35224] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Portal

 

Related note
3220746
CVSS
3.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35171] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3209557
CVSS
6.1

Affected system type
Java
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-32247] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3213826
CVSS
5.4

Affected system type
ABAP
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-31597] Missing Authorization check in SAP S/4HANA(business partner extension for Spain/Slovakia)

 

Related note
3213279
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-31598] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects

 

Related note
3212997
CVSS
7.6

Affected system type
SAP Business One
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-32249] Information Disclosure vulnerability in SAP Business One

 

Related note
3191012
CVSS
7.4

Affected system type
SAP Business One
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-31593] Code Injection vulnerability in SAP Business One

 

Related note
3150463
CVSS
4.9

Affected system type
ABAP
Patchday
2022-07
Released on
2022/07/12

Description
Information Disclosure vulnerability in ABAP Platform

 

Related note
3203079
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-32246] SQL Injection vulnerability in SAP BusinessObjects Business Intelligence Platform (Visual Difference Application)

 

Related note
3194361
CVSS
6.0

Affected system type
BI/BO platform
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35169] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (LCM)

 

Related note
3167430
CVSS
5.6

Affected system type
BI/BO platform
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-31591] Privilege Escalation vulnerability in SAP BusinessObjects (BW Publisher Service)

 

Related note
3211203
CVSS
4.3

Affected system type
SAP Business One
Patchday
2022-07
Released on
2022/07/12

Description
[CVE-2022-35168] Denial of Service vulnerability in SAP Business One

 

Related note
3216161
CVSS
4.3