Security Advisories  

We've created the first of its kind, ABEX Security Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.

The user interface, is designed to be as intuitive as possible but we'd love to hear your feedback and opinions.
We hope you like it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 19 and the highest CVSS score is 9.8.

 

 Severity
SAP© Security advisories 19
 System Types
Affected SAP© system types

 

Related note
2916562
CVSS
6.5

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6270] Missing Authorization check in SAP Netweaver AS ABAP (Banking Services)

Security Advisory

 

Related note
2918924
CVSS
9.8

Affected system type
SAP Cloud Commerce
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6265] Use of Hard-coded Credentials in SAP Commerce and SAP Commerce Datahub

Security Advisory

 

Related note
2918762
CVSS
6.5

Affected system type
Adobe LiveCycle Designer
Patchday
2020-06
Released on
2020/06/09

Description
Multiple vulnerabilities in Adobe LiveCycle Designer 11.0

Security Advisory

 

Related note
2540180
CVSS
6.3

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
Switchable Authorization checks for RFC in Environment, Health & Safety

Security Advisory

 

Related note
2915126
CVSS
6.5

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6260] Incomplete XML Validation in SAP Solution Manager (Trace Analysis)

Security Advisory

 

Related note
2911704
CVSS
5.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA

Security Advisory

 

Related note
2911687
CVSS
5.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA

Security Advisory

 

Related note
2911267
CVSS
4.3

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
Update 1 to Security Note 2752614 - [CVE-2019-0319] Content Injection Vulnerability in SAP Gateway

Security Advisory

 

Related note
2908382
CVSS
4.4

Affected system type
SAP Business One
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6239] Information Disclosure in SAP Business One (Backup Service)

Security Advisory

 

Related note
2906996
CVSS
5.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6268] Missing authorization check in SAP ERP (Statutory Reporting for Insurance Companies)

Security Advisory

 

Related note
2906366
CVSS
8.6

Affected system type
SAP Cloud Commerce
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6264] Information Disclosure in SAP Commerce

Security Advisory

 

Related note
2905836
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6269] Information Disclosure in SAP Business Objects Business Intelligence Platform

Security Advisory

 

Related note
2878935
CVSS
6.1

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6246] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP ( Business Server Pages Test Application SBSPEXT_TABLE)

Security Advisory

 

Related note
2933282
CVSS
8.1

Affected system type
SAP Success Factors
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6279] Missing Authorization Check in SAP SuccessFactors Recruiting

Security Advisory

 

Related note
2931391
CVSS
8.2

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6271] Missing XML Validation in SAP Solution Manager (Problem Context Manager)

Security Advisory

 

Related note
2928570
CVSS
9.8

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
Ghostcat' Apache Tomcat AJP Vulnerability in SAP Liquidity Management for Banking

Security Advisory

 

Related note
2923035
CVSS
4.4

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI

Security Advisory

 

Related note
2878568
CVSS
6.9

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6263] Authentication Bypass in Standalone Clients connecting to SAP NetWeaver AS Java via P4 Protocol

Security Advisory

 

Related note
2912939
CVSS
7.6

Affected system type
ABAP
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6275] Server Side Request Forgery vulnerability in SAP NetWeaver AS ABAP

Security Advisory