Security Advisories  

We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.

The user interface, is designed to be as intuitive as possible but we'd love to hear your feedback and opinions.
We hope you like it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 55 and the highest CVSS score is 9.9.

 

 Severity
SAP© Security advisories 55
 System Types
Affected SAP© system types

 

Related note
2911863
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2021-04
Released on
2021/04/13

Description
Information Disclosure in BOE/CMC application

 

Related note
2818965
CVSS
4.6

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
Clickjacking vulnerability in Runtime Workbench of SAP Process Integration

 

Related note
3005802
CVSS
5.4

Affected system type
ABAP
Patchday
2021-04
Released on
2021/03/23

Description
Cross-Site Request Forgery (CSRF) vulnerability in S/4HANA Finance for advanced payment management

 

Related note
3001824
CVSS
7.4

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-21485] Information Disclosure in SAP NetWeaver AS for Java (Telnet Commands)

 

Related note
3030948
CVSS
4.6

Affected system type
SAP Solution Manager...
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27609] Missing Authorization check in SAP Focused RUN

 

Related note
3024414
CVSS
6.4

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27600 ] Cross-Site Scripting (XSS) vulnerability in SAP Manufacturing Execution (System Rules)

 

Related note
3039649
CVSS
7.5

Affected system type
SAP GUI / Frontend
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27608] Unquoted Search Path in SAPSetup

 

Related note
3017823
CVSS
8.2

Affected system type
SAP Solution Manager
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-21483] Information Disclosure in SAP Solution Manager

 

Related note
3040210
CVSS
9.9

Affected system type
SAP Commerce / SAP...
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27602] Remote Code Execution vulnerability in Source Rules of SAP Commerce

 

Related note
2963592
CVSS
5.4

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27601] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java (Applications based on HTMLB for Java)

 

Related note
3036436
CVSS
6.5

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27604] Potential XXE Vulnerability in SAP Process Integration (ESR Java Mappings)

 

Related note
3017908
CVSS
8.3

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-21482] Information Disclosure in SAP NetWeaver Master Data Management

 

Related note
3028729
CVSS
6.5

Affected system type
ABAP
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27603] Denial of Service (DoS) in SAP NetWeaver AS of ABAP

 

Related note
3025637
CVSS
4.3

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-21492] Content spoofing in NetWeaver AS Java HTTP Service

 

Related note
3012277
CVSS
6.5

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27599] Information Disclosure in SAP Process Integration (Integration Builder Framework)

 

Related note
3036679
CVSS
5.3

Affected system type
ABAP
Patchday
2021-04
Released on
2021/04/13

Description
Update 1 to Security Note 1576763: Potential information disclosure relating to usernames

 

Related note
3027937
CVSS
6.5

Affected system type
Java
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27598] Improper Access Control in SAP NetWeaver AS for Java (Customer Usage Provisioning Servlet)

 

Related note
3035472
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-04
Released on
2021/03/18

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3025054
CVSS
4.3

Affected system type
ABAP
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27605 ] Missing Authorization check in HCM Travel Management Fiori Apps V2

 

Related note
2983436
CVSS
6.5

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21488] Insecure deserialisation in SAP NetWeaver Knowledge Management

 

Related note
2475705
CVSS
6.3

Affected system type
ABAP
Patchday
2021-03
Released on
2021/02/23

Description
Switchable Authorization checks for RFC in In House Cash

 

Related note
2976947
CVSS
4.7

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21491] Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on Web Dynpro Java)

 

Related note
2977001
CVSS
4.7

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on HTMLB for Java)

 

Related note
3027767
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-27592] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3022622
CVSS
9.9

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence

 

Related note
3017378
CVSS
7.7

Affected system type
SAP HANA Platform
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21484] Possible authentication bypass in SAP HANA LDAP scenarios

 

Related note
3027758
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-03
Released on
2021/03/09

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3023778
CVSS
6.8

Affected system type
ABAP
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21487] Missing Authorization Check in Payment Engine

 

Related note
3007888
CVSS
6.8

Affected system type
ABAP
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21486] Missing Authorization check in SAP Enterprise Financial Services( Bank Customer Accounts )

 

Related note
2978151
CVSS
4.7

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
Reverse tabnabbing issue in Unified Rendering based frameworks in NetWeaver Application Server Java

 

Related note
3022422
CVSS
9.6

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21481] Missing Authorization Check in SAP NetWeaver AS JAVA (MigrationService)

 

Related note
2835240
CVSS
5.4

Affected system type
Java
Patchday
2021-02
Released on
2021/02/09

Description
Clickjacking vulnerability in Cloud Integration Content of SAP Process Integration

 

Related note
2994289
CVSS
4.1

Affected system type
ABAP
Patchday
2021-02
Released on
2021/02/09

Description
Reverse Tabnabbing vulnerability within SAP CRM WebClient UI

 

Related note
3000897
CVSS
4.0

Affected system type
Java
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21475] Directory Traversal vulnerability in SAP NetWeaver Master Data Management 7.1

 

Related note
2990992
CVSS
5.4

Affected system type
ABAP
Patchday
2021-02
Released on
2021/02/09

Description
Missing Authorization Checks in the Monitor Data and My Data Collections Apps

 

Related note
2935791
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21444] Clickjacking vulnerability in SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad)

 

Related note
2998173
CVSS
6.3

Affected system type
SAP Netweaver
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21472] Server password not set during installation of SAP NetWeaver Master Data Management 7.1

 

Related note
2992154
CVSS
4.1

Affected system type
SAP HANA Platform
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21474] SAML Assertion Signature MD5 Digest Algorithm Vulnerability in SAP HANA Database

 

Related note
3014121
CVSS
9.9

Affected system type
SAP Commerce Cloud
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21477] Remote Code Execution vulnerability in SAP Commerce

 

Related note
2973428
CVSS
4.7

Affected system type
Kernal
Patchday
2021-02
Released on
2021/02/09

Description
Reverse Tabnabbing vulnerability within SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML)

 

Related note
2974582
CVSS
4.7

Affected system type
ABAP
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21478] Reverse Tabnabbing vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP)

 

Related note
2818963
CVSS
0.0

Affected system type
Java
Patchday
2021-02
Released on
2021/02/09

Description
Clickjacking vulnerability in Adapter Runtime of SAP Process Integration

 

Related note
3002617
CVSS
4.3

Affected system type
Visual Enterprise
Patchday
2021-01
Released on
2021/01/12

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
2999854
CVSS
9.9

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21466] Code Injection in SAP Business Warehouse and SAP BW/4HANA

 

Related note
2992269
CVSS
5.3

Affected system type
SAP GUI / Frontend
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21448] Information Disclosure in SAP GUI for Windows

 

Related note
2984034
CVSS
5.4

Affected system type
SAP Commerce Cloud
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21445] Header Manipulation vulnerability in SAP Commerce Cloud

 

Related note
3000291
CVSS
3.6

Affected system type
Analysis for Office
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21470] XML External Entity vulnerability in SAP EPM add-in

 

Related note
2965154
CVSS
5.4

Affected system type
BI/BO platform
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21447] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)

 

Related note
2986980
CVSS
9.9

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21465] Multiple vulnerabilities in SAP Business Warehouse (Database Interface)

 

Related note
3000306
CVSS
7.5

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21446] Denial of service (DOS) in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
2743329
CVSS
6.3

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
Switchable authorization checks for RFC module in In-House-Cash.

 

Related note
3001373
CVSS
8.9

Affected system type
Cloud Foundry
Patchday
2021-01
Released on
2020/12/22

Description
Information Disclosure in Central Order

 

Related note
2665387
CVSS
5.5

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
Cross-Site Request Forgery (CSRF) vulnerability in Cash Management

 

Related note
3008422
CVSS
4.3

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21467] Missing Authorization check in SAP Banking Services (Generic Market Data)

 

Related note
2993032
CVSS
5.3

Affected system type
Java
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21469] Information Disclosure in SAP NetWeaver Master Data Management