Security Advisories  

We've created the first of its kind, ABEX Security Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.

The user interface, is designed to be as intuitive as possible but we'd love to hear your feedback and opinions.
We hope you like it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 171 and the highest CVSS score is 10.0.

 

 Severity
SAP© Security advisories 171
 System Types
Affected SAP© system types

 

Related note
2969828
CVSS
10.0

Affected system type
Solution Manager
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6364] OS Command Injection Vulnerability in CA Introscope Enterprise Manager (Affected Products: SAP Solution Manager and SAP Focused Run)

Security Advisory

 

Related note
2969457
CVSS
7.6

Affected system type
Java
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6366] Missing XML Validation in SAP NetWeaver (Compare Systems)

Security Advisory

 

Related note
2939419
CVSS
4.8

Affected system type
SAP NetWeaver Development Infrastructure (NWDI)
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6370] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (DI Design Time Repository)

Security Advisory

 

Related note
2971638
CVSS
7.5

Affected system type
SAP Solution Manager & SAP Focused Run
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6369] Hard-coded Credentials in CA Introscope Enterprise Manager (Affected products: SAP Solution Manager and SAP Focused Run)

Security Advisory

 

Related note
2963137
CVSS
4.3

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6371] Information disclosure in SAP NetWeaver AS ABAP via the POWL Test Feeder endpoint

Security Advisory

 

Related note
2973497
CVSS
5.7

Affected system type
SAP 3D Visual Eneprise
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6315] Multiple Vulnerabilities in SAP 3D Visual Enterprise Viewer

Security Advisory

 

Related note
2953212
CVSS
4.3

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6362] Incorrect Authorization in SAP Banking Services

Security Advisory

 

Related note
2945581
CVSS
4.7

Affected system type
SAP CRM UI
Patchday
2020-10
Released on
2020/09/22

Description
Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI

Security Advisory

 

Related note
2960329
CVSS
4.4

Affected system type
SAP Enterprise Portal (Fiori Framework)
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6323] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (Fiori Framework Page)

Security Advisory

 

Related note
2873099
CVSS
5.4

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
Missing Authorization check in EHS Task Definition attachments

Security Advisory

 

Related note
2956398
CVSS
6.1

Affected system type
Java
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6319] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java

Security Advisory

 

Related note
2965287
CVSS
3.7

Affected system type
SAP Commerce Cloud
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6363] Insufficient Session Expiration in SAP Commerce Cloud

Security Advisory

 

Related note
2973100
CVSS
3.6

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
Missing Authorization check in Manage Substitutions - Products and Manage Exclusions - Products

Security Advisory

 

Related note
2960825
CVSS
5.4

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6368] Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation

Security Advisory

 

Related note
2955963
CVSS
4.3

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
Cross-Site Request Forgery (CSRF) in SAP Marketing

Security Advisory

 

Related note
2883638
CVSS
6.5

Affected system type
ABAP
Patchday
2020-10
Released on
2020/10/13

Description
Information Disclosure in Supplier Relationship Management

Security Advisory

 

Related note
2972661
CVSS
8.2

Affected system type
Java
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6367] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Composite Application Framework

Security Advisory

 

Related note
2917381
CVSS
5.4

Affected system type
SAP Commerce Cloud
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6272] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Cloud

Security Advisory

 

Related note
2965315
CVSS
4.7

Affected system type
Java
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6365] Reverse Tabnabbing vulnerability in SAP NetWeaver AS Java Start Page

Security Advisory

 

Related note
2943844
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6308] Server-Side Request Forgery vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Services)

Security Advisory

 

Related note
2606194
CVSS
4.4

Affected system type
ABAP
Patchday
2020-10
Released on
2020/09/09

Description
Cross-Site Scripting (XSS) vulnerability in CRM Interaction Center

Security Advisory

 

Related note
2924859
CVSS
6.5

Affected system type
ABAP
Patchday
2020-09
Released on
2020/08/25

Description
Missing Authorization check in Discrete Industries and Mill Products

Security Advisory

 

Related note
2961991
CVSS
9.6

Affected system type
SAP Marketing
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6320] Improper Access Control in SAP Marketing (Mobile Channel Servlet)

Security Advisory

 

Related note
2531082
CVSS
6.3

Affected system type
ABAP
Patchday
2020-09
Released on
2019/03/12

Description
Switchable Authorization checks for RFC BCA_DIM_LOANS_APPLOG_UPDATE in Loans (FI-CAX-FS)

Security Advisory

 

Related note
2930128
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6325] Multiple Vulnerabilities in SAP BusinessObjects Business Intelligence Platform

Security Advisory

 

Related note
2865229
CVSS
4.8

Affected system type
SAP UI5
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6283] Cross-Site Scripting (XSS) vulnerability in SAP Fiori(Launchpad)

Security Advisory

 

Related note
2958563
CVSS
9.1

Affected system type
ABAP
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6318] Code Injection vulnerability in SAP NetWeaver (ABAP Server) and ABAP Platform

Security Advisory

 

Related note
2953203
CVSS
2.6

Affected system type
SAP Adaptive Server Enterprise (ASE)
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6317] Information Disclosure in SAP Adaptive Server Enterprise

Security Advisory

 

Related note
2953112
CVSS
5.4

Affected system type
Java
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6326] Cross-Site Scripting (XSS) vulnerabilities in SAP NetWeaver AS Java

Security Advisory

 

Related note
2951325
CVSS
6.5

Affected system type
ABAP
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6311] Improper Authorization Checks in Banking services from SAP Bank Analyzer and SAP S/4HANA Financial Products

Security Advisory

 

Related note
2948239
CVSS
6.1

Affected system type
ABAP
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6324] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Test Application)

Security Advisory

 

Related note
2934451
CVSS
6.4

Affected system type
SAP Commerce Cloud
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6302] Session Fixation in SAP Commerce

Security Advisory

 

Related note
2960815
CVSS
4.3

Affected system type
SAP 3D Visual Eneprise
Patchday
2020-09
Released on
2020/09/08

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

Security Advisory

 

Related note
2928635
CVSS
9.0

Affected system type
Java
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6284] Cross-Site Scripting (XSS) in SAP NetWeaver (Knowledge Management)

Security Advisory

 

Related note
2941510
CVSS
4.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6299] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform

Security Advisory

 

Related note
2941332
CVSS
7.0

Affected system type
SAP Adaptive Server Enterprise (ASE)
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6295] Information Disclosure in SAP Adaptive Server Enterprise

Security Advisory

 

Related note
2941667
CVSS
8.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6296] Code Injection Vulnerability in SAP NetWeaver (ABAP) and ABAP Platform

Security Advisory

 

Related note
2925827
CVSS
4.8

Affected system type
BI/BO platform
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6300] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(Central Management Console)

Security Advisory

 

Related note
2756551
CVSS
6.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
Missing Authorization check in TSW Supply Chain Visualization

Security Advisory

 

Related note
2939685
CVSS
8.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6298] Missing Authorization check in SAP Banking Services (Generic Market Data)

Security Advisory

 

Related note
2754546
CVSS
5.0

Affected system type
Lumira Designer
Patchday
2020-08
Released on
2020/08/11

Description
Potential information disclosure in Lumira Designer

Security Advisory

 

Related note
2885671
CVSS
4.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6273] Missing Authorization check in SAP S/4 HANA (Fiori UI for General Ledger Accounting)

Security Advisory

 

Related note
2938162
CVSS
7.3

Affected system type
Java
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6293] Unrestricted File Upload in SAP NetWeaver (Knowledge Management)

Security Advisory

 

Related note
2944988
CVSS
4.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6310] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform

Security Advisory

 

Related note
2921615
CVSS
5.5

Affected system type
BI/BO platform
Patchday
2020-08
Released on
2020/08/11

Description
BI Platform stores SAP BW Authentication Password as clear text

Security Advisory

 

Related note
2941315
CVSS
7.5

Affected system type
Java
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6309] Missing Authentication check in SAP NetWeaver AS JAVA

Security Advisory

 

Related note
2927956
CVSS
8.5

Affected system type
BI/BO platform
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6294] Missing Authentication check in SAP BusinessObjects Business Intelligence Platform

Security Advisory

 

Related note
2948317
CVSS
6.1

Affected system type
SAP Commerce
Patchday
2020-08
Released on
2020/08/11

Description
Vulnerabilities in open source libraries used in SAP Commerce

Security Advisory

 

Related note
2949196
CVSS
5.4

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6301] Missing Authorization check in SAP ERP (HCM Travel Management)

Security Advisory

 

Related note
2941170
CVSS
6.1

Affected system type
SAPGUI / Frontend
Patchday
2020-08
Released on
2020/08/11

Description
Cross-Site Scripting (XSS) vulnerabilities in modified jQuery bundled with SAPUI5

Security Advisory

 

Related note
2593479
CVSS
3.9

Affected system type
Java
Patchday
2020-08
Released on
2018/06/15

Description
Checking server certificates and host name of managed systems

Security Advisory

 

Related note
2940823
CVSS
6.3

Affected system type
SAP Data Hub
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6297] Information Disclosure in SAP Data Intelligence

Security Advisory

 

Related note
2896025
CVSS
5.8

Affected system type
Java
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6282] Server-Side Request Forgery in SAP NetWeaver AS JAVA (IIOP service)

Security Advisory

 

Related note
2934135
CVSS
10.0

Affected system type
Java
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6287] Multiple Vulnerabilities in SAP NetWeaver AS JAVA (LM Configuration Wizard)

Security Advisory

 

Related note
2912708
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6278] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC)

Security Advisory

 

Related note
2874738
CVSS
3.8

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Missing Authorization Check in S4 ACR Brazil Option

Security Advisory

 

Related note
2927373
CVSS
2.7

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6280] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform

Security Advisory

 

Related note
2537961
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Switchable Authorization checks for RFC in MM-PUR-GF

Security Advisory

 

Related note
2847817
CVSS
4.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Missing Authorization check in Travel Management

Security Advisory

 

Related note
2758000
CVSS
6.3

Affected system type
SAP Disclosure Management
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6267] Multiple vulnerabilities in SAP Disclosure Management

Security Advisory

 

Related note
2603398
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Missing authorization check in Allocation Management

Security Advisory

 

Related note
2849967
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6276] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(Bipodata)

Security Advisory

 

Related note
2486446
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/07/14

Description
Missing Authorization check in Pricat Inbound and Pricat Outbound

Security Advisory

 

Related note
2091403
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2015/08/11

Description
Directory traversal in BC-MID-ICF

Security Advisory

 

Related note
2541823
CVSS
6.3

Affected system type
ABAP
Patchday
2020-07
Released on
2020/06/09

Description
Switchable authorization checks for RFC in SAP CRM (external billing)

Security Advisory

 

Related note
2932473
CVSS
7.7

Affected system type
Java
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6285] Information Disclosure in SAP NetWeaver (XMLToolkit for Java)

Security Advisory

 

Related note
2917743
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6281] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(BI Launch pad)

Security Advisory

 

Related note
2878935
CVSS
6.1

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6246] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP ( Business Server Pages Test Application SBSPEXT_TABLE)

Security Advisory

 

Related note
2916562
CVSS
6.5

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6270] Missing Authorization check in SAP Netweaver AS ABAP (Banking Services)

Security Advisory

 

Related note
2918762
CVSS
6.5

Affected system type
Adobe LiveCycle Designer
Patchday
2020-06
Released on
2020/06/09

Description
Multiple vulnerabilities in Adobe LiveCycle Designer 11.0

Security Advisory

 

Related note
2918924
CVSS
9.8

Affected system type
SAP Cloud Commerce
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6265] Use of Hard-coded Credentials in SAP Commerce and SAP Commerce Datahub

Security Advisory

 

Related note
2540180
CVSS
6.3

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
Switchable Authorization checks for RFC in Environment, Health & Safety

Security Advisory

 

Related note
2908382
CVSS
4.4

Affected system type
SAP Business One
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6239] Information Disclosure in SAP Business One (Backup Service)

Security Advisory

 

Related note
2911267
CVSS
4.3

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
Update 1 to Security Note 2752614 - [CVE-2019-0319] Content Injection Vulnerability in SAP Gateway

Security Advisory

 

Related note
2911687
CVSS
5.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA

Security Advisory

 

Related note
2911704
CVSS
5.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA

Security Advisory

 

Related note
2915126
CVSS
6.5

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6260] Incomplete XML Validation in SAP Solution Manager (Trace Analysis)

Security Advisory

 

Related note
2905836
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6269] Information Disclosure in SAP Business Objects Business Intelligence Platform

Security Advisory

 

Related note
2906366
CVSS
8.6

Affected system type
SAP Cloud Commerce
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6264] Information Disclosure in SAP Commerce

Security Advisory

 

Related note
2906996
CVSS
5.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6268] Missing authorization check in SAP ERP (Statutory Reporting for Insurance Companies)

Security Advisory

 

Related note
2923035
CVSS
4.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI

Security Advisory

 

Related note
2928570
CVSS
9.8

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
Ghostcat' Apache Tomcat AJP Vulnerability in SAP Liquidity Management for Banking

Security Advisory

 

Related note
2931391
CVSS
8.2

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6271] Missing XML Validation in SAP Solution Manager (Problem Context Manager)

Security Advisory

 

Related note
2933282
CVSS
8.1

Affected system type
SAP Success Factors
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6279] Missing Authorization Check in SAP SuccessFactors Recruiting

Security Advisory

 

Related note
2878568
CVSS
6.9

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6263] Authentication Bypass in Standalone Clients connecting to SAP NetWeaver AS Java via P4 Protocol

Security Advisory

 

Related note
2912939
CVSS
7.6

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6275] Server Side Request Forgery vulnerability in SAP NetWeaver AS ABAP

Security Advisory

 

Related note
2917090
CVSS
9.0

Affected system type
SAP Adaptive Server Enterprise (ASE)
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6252] Information Disclosure in SAP Adaptive Server Enterprise (Cockpit)

Security Advisory

 

Related note
2917022
CVSS
6.8

Affected system type
SAP Adaptive Server Enterprise (ASE)
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6250] Information Disclosure in SAP Adaptive Server Enterprise

Security Advisory

 

Related note
2917273
CVSS
7.2

Affected system type
SAP Adaptive Server Enterprise (ASE)
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6253] SQL Injection vulnerability in SAP Adaptive Server Enterprise (Web Services)

Security Advisory

 

Related note
2747062
CVSS
5.0

Affected system type
ABAP
Patchday
2020-05
Released on
2020/05/12

Description
This note has been re-released without changes. - Cross-Site Request Forgery (CSRF) vulnerability in SAP Web Dynpro ABAP

Security Advisory

 

Related note
2913293
CVSS
6.1

Affected system type
SAP Enterprise Threat Detection
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6254] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Threat Detection

Security Advisory

 

Related note
2915429
CVSS
4.3

Affected system type
SAP IDM
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6258] Missing Authorization check in SAP Identity Management

Security Advisory

 

Related note
2915585
CVSS
8.0

Affected system type
SAP Adaptive Server Enterprise (ASE)
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6243] Code Injection in SAP Adaptive Server Enterprise (XP Server on Windows Platform)

Security Advisory

 

Related note
2916927
CVSS
8.8

Affected system type
SAP Adaptive Server Enterprise (ASE)
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6241] SQL Injection vulnerability in SAP Adaptive Server Enterprise

Security Advisory

 

Related note
2835979
CVSS
9.9

Affected system type
ABAP
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6262] Code Injection vulnerability in Service Data Download

Security Advisory

 

Related note
2917275
CVSS
9.1

Affected system type
SAP Adaptive Server Enterprise (ASE)
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6248] Code injection in SAP Adaptive Server Enterprise (Backup Server)

Security Advisory

 

Related note
2920548
CVSS
6.5

Affected system type
SAP Adaptive Server Enterprise (ASE)
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6259] Missing authorization check in SAP Adaptive Server Enterprise

Security Advisory

 

Related note
2897612
CVSS
4.7

Affected system type
ABAP
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6214] Incorrect Authorization in SAP S/4HANA (Financial Products Subledger)

Security Advisory

 

Related note
2876059
CVSS
6.1

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6216] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform (BILaunchpad/ Opendocument)

Security Advisory

 

Related note
2826528
CVSS
6.2

Affected system type
Java
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6224] Information Disclosure in SAP NetWeaver Application Server Java (HTTP Service)

Security Advisory

 

Related note
2888556
CVSS
5.3

Affected system type
SAP Commerce Cloud
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6232] Missing Authorization check in SAP Commerce

Security Advisory

 

Related note
2879132
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6226] Cross-Site Scripting (XSS) vulnerabilities in SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface)

Security Advisory

 

Related note
2877226
CVSS
6.3

Affected system type
ABAP
Patchday
2020-04
Released on
2020/03/12

Description
Switchable Authorization checks in SAP Supplier Relationship Management

Security Advisory

 

Related note
2872782
CVSS
6.1

Affected system type
ABAP
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6215] URL Redirection vulnerability in SAP NetWeaver AS ABAP – Business Server Pages Test Application IT00

Security Advisory

 

Related note
2872752
CVSS
6.1

Affected system type
ABAP
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6213]Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP(Business Server Pages Test Application SBSPEXT_PHTMLB)

Security Advisory

 

Related note
2866752
CVSS
5.3

Affected system type
SAPGUI / Frontend
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6228] Missing Integrity Check in SAP BUSINESS CLIENT

Security Advisory

 

Related note
2863396
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6227] Remote unauthenticated log injection in SAP Business Objects Business Intelligence Platform (CMS / Auditing issues)

Security Advisory

 

Related note
2863731
CVSS
9.1

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6219] Deserialization of Untrusted Data in SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer)

Security Advisory

 

Related note
2864966
CVSS
6.3

Affected system type
ABAP
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6212] Missing Authorization Check in SAP ERP & S/4 HANA (Egypt localized Withholding Tax reports)

Security Advisory

 

Related note
2900374
CVSS
6.1

Affected system type
ABAP
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6229] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME)

Security Advisory

 

Related note
2902456
CVSS
7.2

Affected system type
SAP Landscape Management
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6236] Privilege Escalation in SAP Landscape Management (SAP Adaptive Extensions)

Security Advisory

 

Related note
2900118
CVSS
9.1

Affected system type
SAP Orient DB
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6230] Code Injection vulnerability in SAP OrientDB 3.0

Security Advisory

 

Related note
2878507
CVSS
6.4

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6195] Multiple vulnerabilities in SAP Business Objects Business Intelligence Platform

Security Advisory

 

Related note
2898077
CVSS
7.5

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6237] Information Disclosure in SAP Business Objects Business Intelligence Platform (dswsbobje Web Application)

Security Advisory

 

Related note
2896682
CVSS
9.1

Affected system type
Java
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6225] Directory Traversal vulnerability in SAP NetWeaver (Knowledge Management)

Security Advisory

 

Related note
2906994
CVSS
8.6

Affected system type
SAP Solution Manager
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6235] Missing authentication check in SAP Solution Manager (Diagnostics Agent )

Security Advisory

 

Related note
2904796
CVSS
4.3

Affected system type
ABAP
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6233] Missing Authorization Check in SAP S/4 HANA (Financial Products Subledger and Banking Services)

Security Advisory

 

Related note
2880804
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6222] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)

Security Advisory

 

Related note
2904480
CVSS
9.3

Affected system type
SAP Commerce Cloud
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6238] Missing XML Validation vulnerability in SAP Commerce

Security Advisory

 

Related note
2872545
CVSS
6.1

Affected system type
ABAP
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6217] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (Business Server Pages Test Application IT05)

Security Advisory

 

Related note
2902645
CVSS
7.2

Affected system type
SAP Host Agent
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6234] Privilege Escalation in SAP Host Agent

Security Advisory

 

Related note
2876813
CVSS
6.1

Affected system type
SAP Commerce Cloud
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6201] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Cloud (testweb extension)

Security Advisory

 

Related note
2892570
CVSS
5.9

Affected system type
ABAP Development Tools
Patchday
2020-03
Released on
2020/03/10

Description
Missing XML Validation vulnerability in ABAP Development Tools

Security Advisory

 

Related note
2859004
CVSS
4.7

Affected system type
SAP CPI DS
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6206] Cross-Site Request Forgery in SAP Cloud Platform Integration for data services

Security Advisory

 

Related note
2871167
CVSS
5.4

Affected system type
ABAP
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6199] Missing Authorization check in SAP ERP and S/4 HANA (MENA Certificate Management)

Security Advisory

 

Related note
2858044
CVSS
7.5

Affected system type
SAP Disclosure Management
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6209] Missing Authorization check in SAP Disclosure Management

Security Advisory

 

Related note
2845363
CVSS
3.8

Affected system type
SAP Enable Now
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6197] Insufficient session expiration in SAP Enable Now Manager

Security Advisory

 

Related note
2880664
CVSS
5.4

Affected system type
SAP Enable Now
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6178] Insufficient session expiration in SAP Enable Now Manager

Security Advisory

 

Related note
2864462
CVSS
4.7

Affected system type
ABAP
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6210] Cross-Site Scripting (XSS) vulnerability in SAP Fiori Launchpad

Security Advisory

 

Related note
1966029
CVSS
7.3

Affected system type
ABAP
Patchday
2020-03
Released on
2020/03/10

Description
Directory traversal in SAP Environment Health and Safety

Security Advisory

 

Related note
2841874
CVSS
4.3

Affected system type
ABAP
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6204] Missing Authorization check in SAP Treasury and Risk Management (Transaction Management)

Security Advisory

 

Related note
2660005
CVSS
7.2

Affected system type
SAP MaxDB
Patchday
2020-03
Released on
2018/08/14

Description
[CVE-2018-2450] SQL Injection Vulnerability in SAP MaxDB/liveCache

Security Advisory

 

Related note
2826782
CVSS
7.5

Affected system type
BI/BO platform
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6196] Denial of service (DOS) in SAP BusinessObjects Mobile (MobileBIService)

Security Advisory

 

Related note
2806198
CVSS
9.1

Affected system type
Java
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6203] Path Manipulation in SAP NetWeaver UDDI Server(Services Registry)

Security Advisory

 

Related note
2884910
CVSS
6.1

Affected system type
ABAP
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6205] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP Business Server Pages  (Smart Forms)

Security Advisory

 

Related note
2845377
CVSS
9.8

Affected system type
Java
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6198] Missing Authentication check in SAP Solution Manager (Diagnostics Agent)

Security Advisory

 

Related note
2890213
CVSS
10.0

Affected system type
Java
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6207] Missing Authentication Check in SAP Solution Manager (User-Experience Monitoring)

Security Advisory

 

Related note
2847787
CVSS
5.5

Affected system type
Java
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6202] Missing XML Validation in SAP NetWeaver Application Server Java (User Management Engine)

Security Advisory

 

Related note
2876413
CVSS
5.4

Affected system type
SAP Commerce Cloud
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6200] Cross-Site-Scripting in SAP Commerce Cloud (SmartEdit extension)

Security Advisory

 

Related note
2731871
CVSS
6.3

Affected system type
ABAP
Patchday
2020-03
Released on
2020/03/10

Description
Missing Authorization check in Commercial Project Management

Security Advisory

 

Related note
2861301
CVSS
8.2

Affected system type
BI/BO platform
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6208] Remote Code Execution in SAP Business Objects Business Intelligence Platform (Crystal Reports)

Security Advisory

 

Related note
2057196
CVSS
6.3

Affected system type
ABAP
Patchday
2020-02
Released on
2014/09/17

Description
Missing authorization check in IS-B-BCA-AM

Security Advisory

 

Related note
2857511
CVSS
6.3

Affected system type
ABAP
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6188] Missing Authorization check in SAP ERP and S/4 HANA (VAT Pro-Rata reports)

Security Advisory

 

Related note
2688383
CVSS
6.3

Affected system type
ABAP
Patchday
2020-02
Released on
2020/02/11

Description
Missing authorization check in Dangerous Goods Management of EHS Services in SCM

Security Advisory

 

Related note
2877968
CVSS
7.2

Affected system type
SAP Landscape Management
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6192] Missing Input Validation in SAP Landscape Management

Security Advisory

 

Related note
2870067
CVSS
6.5

Affected system type
ABAP
Patchday
2020-02
Released on
2020/02/11

Description
Update 1 to Security Note 2736825 - [CVE-2019-0271] Denial of Service via XML External Entity (XXE) vulnerability in ABAP Server

Security Advisory

 

Related note
2736825
CVSS
6.5

Affected system type
ABAP
Patchday
2020-02
Released on
2019/03/12

Description
[CVE-2019-0271] Denial of Service via XML External Entity (XXE) vulnerability in ABAP Server

Security Advisory

 

Related note
2864415
CVSS
4.9

Affected system type
Java
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6187]Missing XML Validation vulnerability in SAP NetWeaver(Guided Procedures)

Security Advisory

 

Related note
2622660
CVSS
9.8

Affected system type
SAPGUI / Frontend
Patchday
2020-02
Released on
2018/04/10

Description
Security updates for the browser control Google Chromium delivered with SAP Business Client

Security Advisory

 

Related note
2838835
CVSS
5.3

Affected system type
Java
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6190]Information Disclosure in SAP NetWeaver AS Java (Heap Dump Application)

Security Advisory

 

Related note
2880869
CVSS
6.1

Affected system type
ABAP
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6184 ]Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver and SAP S/4HANA

Security Advisory

 

Related note
2822074
CVSS
6.6

Affected system type
ABAP
Patchday
2020-02
Released on
2020/01/14

Description
Missing Authorization check in SAP NetWeaver (ABAP Server)

Security Advisory

 

Related note
2880993
CVSS
4.3

Affected system type
SAP Mobile Platform
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6177] Missing XML Validation vulnerability in SAP Mobile Platform

Security Advisory

 

Related note
2880744
CVSS
5.8

Affected system type
ABAP
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6181] HTTP Response Splitting vulnerability in SAP NetWeaver and ABAP Platform

Security Advisory

 

Related note
2878030
CVSS
7.2

Affected system type
SAP Landscape Management
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6191] Missing Input Validation in SAP Landscape Management

Security Advisory

 

Related note
2873012
CVSS
6.1

Affected system type
Java
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6193]Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (Knowledge Management ICE Service)

Security Advisory

 

Related note
2841053
CVSS
7.5

Affected system type
SAP Host Agent
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6186] Denial of Service (DOS) Vulnerability in SAP Host Agent

Security Advisory

 

Related note
2836445
CVSS
5.3

Affected system type
SAP Host Agent
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6183] Unprivileged Access to technical data using SAPOSCOL of SAP Host Agent

Security Advisory

 

Related note
2695776
CVSS
7.4

Affected system type
SAP Mobile Platform
Patchday
2020-02
Released on
2020/01/14

Description
Missing Authorization Check in SAP Mobile Platform Native SDK, Android

Security Advisory

 

Related note
2695210
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2020-02
Released on
2020/02/11

Description
[CVE-2020-6189] Information Disclosure in SAP BusinessObjects BI Central Management Console

Security Advisory

 

Related note
2848498
CVSS
5.9

Affected system type
Kernel
Patchday
2020-01
Released on
2020/01/14

Description
[CVE-2020-6304] Denial of service (DOS) in SAP NetWeaver Internet Communication Manager

Security Advisory

 

Related note
2495462
CVSS
6.3

Affected system type
ABAP
Patchday
2020-01
Released on
2020/01/14

Description
Switchable Authorization checks for RFC in SAP Leasing

Security Advisory

 

Related note
2871877
CVSS
8.3

Affected system type
ABAP
Patchday
2020-01
Released on
2019/12/24

Description
Multiple security vulnerabilities in SAP EAM, add-on for MRO 4.0 by HCL for SAP S/4HANA 1809

Security Advisory

 

Related note
2863397
CVSS
4.3

Affected system type
ABAP
Patchday
2020-01
Released on
2020/01/14

Description
[CVE-2020-6307] Missing Authorization Check in Automated Note Search Tool (SAP_BASIS)

Security Advisory

 

Related note
2845401
CVSS
5.4

Affected system type
Realtech
Patchday
2020-01
Released on
2020/01/14

Description
Missing Authorization check in Realtech RTCISM 100

Security Advisory

 

Related note
2772325
CVSS
5.4

Affected system type
SAP Disclosure Management
Patchday
2020-01
Released on
2020/01/13

Description
[CVE-2020-6303] Improper input validation in SAP Disclosure Management

Security Advisory

 

Related note
2863743
CVSS
6.1

Affected system type
Java
Patchday
2020-01
Released on
2020/01/14

Description
[CVE-2020-6305] Cross-Site Scripting (XSS) vulnerability in Rest Adapter of SAP Process Integration

Security Advisory

 

Related note
2865348
CVSS
2.7

Affected system type
ABAP
Patchday
2020-01
Released on
2020/01/14

Description
[CVE-2020-6306] Missing Authorization check in SAP Leasing

Security Advisory

 

Related note
2142551
CVSS
4.3

Affected system type
ABAP
Patchday
2020-01
Released on
2016/07/12

Description
Whitelist service for Clickjacking Framing Protection in AS ABAP

Security Advisory

 

Related note
2165892
CVSS
6.3

Affected system type
ABAP
Patchday
2020-01
Released on
2020/01/14

Description
Missing authorization check in Transaction Manager

Security Advisory

 

Related note
2843016
CVSS
4.3

Affected system type
ABAP
Patchday
2020-01
Released on
2019/11/12

Description
[CVE-2019-0388] Content spoofing vulnerability in UI5 HTTP Handler

Security Advisory