We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.
We hope you enjoy using it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 19 and the highest CVSS score is 9.0.

 

 Severity
SAP© Security advisories 19
 System Types
Affected SAP© system types

 

Related note
2949196
CVSS
5.4

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6301] Missing Authorization check in SAP ERP (HCM Travel Management)

 

Related note
2948317
CVSS
6.1

Affected system type
SAP Commerce
Patchday
2020-08
Released on
2020/08/11

Description
Vulnerabilities in open source libraries used in SAP Commerce

 

Related note
2928635
CVSS
9.0

Affected system type
Java
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6284] Cross-Site Scripting (XSS) in SAP NetWeaver (Knowledge Management)

 

Related note
2927956
CVSS
8.5

Affected system type
BI/BO platform
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6294] Missing Authentication check in SAP BusinessObjects Business Intelligence Platform

 

Related note
2885671
CVSS
4.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6273] Missing Authorization check in SAP S/4 HANA (Fiori UI for General Ledger Accounting)

 

Related note
2938162
CVSS
7.3

Affected system type
Java
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6293] Unrestricted File Upload in SAP NetWeaver (Knowledge Management)

 

Related note
2941315
CVSS
7.5

Affected system type
Java
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6309] Missing Authentication check in SAP NetWeaver AS JAVA

 

Related note
2921615
CVSS
5.5

Affected system type
BI/BO platform
Patchday
2020-08
Released on
2020/08/11

Description
BI Platform stores SAP BW Authentication Password as clear text

 

Related note
2944988
CVSS
4.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6310] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform

 

Related note
2754546
CVSS
5.0

Affected system type
Lumira Designer
Patchday
2020-08
Released on
2020/08/11

Description
Potential information disclosure in Lumira Designer

 

Related note
2756551
CVSS
6.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
Missing Authorization check in TSW Supply Chain Visualization

 

Related note
2939685
CVSS
8.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6298] Missing Authorization check in SAP Banking Services (Generic Market Data)

 

Related note
2925827
CVSS
4.8

Affected system type
BI/BO platform
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6300] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(Central Management Console)

 

Related note
2941667
CVSS
8.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6296] Code Injection Vulnerability in SAP NetWeaver (ABAP) and ABAP Platform

 

Related note
2941332
CVSS
7.0

Affected system type
SAP Adaptive Server...
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6295] Information Disclosure in SAP Adaptive Server Enterprise

 

Related note
2941510
CVSS
4.3

Affected system type
ABAP
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6299] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform

 

Related note
2940823
CVSS
6.3

Affected system type
SAP Data Hub
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6297] Information Disclosure in SAP Data Intelligence

 

Related note
2593479
CVSS
3.9

Affected system type
Java
Patchday
2020-08
Released on
2018/06/15

Description
Checking server certificates and host name of managed systems

 

Related note
2941170
CVSS
6.1

Affected system type
SAP GUI / Frontend
Patchday
2020-08
Released on
2020/08/11

Description
Cross-Site Scripting (XSS) vulnerabilities in modified jQuery bundled with SAPUI5

 

 
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2024 by SecurityBridge GmbH

v35.0