Security Advisories  

We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.

The user interface, is designed to be as intuitive as possible but we'd love to hear your feedback and opinions.
We hope you like it!
× Hey there! Glad you made it.
We have found 9 security advices for you to review.

 

 Severity
SAP© Security advisories 9
 System Types
Affected SAP© system types

 

Related note
2978151
CVSS
4.7

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
Reverse tabnabbing issue in Unified Rendering based frameworks in NetWeaver Application Server Java

 

Related note
2475705
CVSS
6.3

Affected system type
ABAP
Patchday
2021-03
Released on
2021/02/23

Description
Switchable Authorization checks for RFC in In House Cash

 

Related note
2976947
CVSS
4.7

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21491] Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on Web Dynpro Java)

 

Related note
3027767
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-27592] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
2977001
CVSS
4.7

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on HTMLB for Java)

 

Related note
3027758
CVSS
4.3

Affected system type
SAP 3D Visual Enterprise
Patchday
2021-03
Released on
2021/03/09

Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer

 

Related note
3023778
CVSS
6.8

Affected system type
ABAP
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21487] Missing Authorization Check in Payment Engine

 

Related note
3007888
CVSS
6.8

Affected system type
ABAP
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21486] Missing Authorization check in SAP Enterprise Financial Services( Bank Customer Accounts )

 

Related note
2983436
CVSS
6.5

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21488] Insecure deserialisation in SAP NetWeaver Knowledge Management

 

 
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2024 by SecurityBridge GmbH

v34.3