Security Advisories  

We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.

The user interface, is designed to be as intuitive as possible but we'd love to hear your feedback and opinions.
We hope you like it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 19 and the highest CVSS score is 9.8.

 

 Severity
SAP© Security advisories 19
 System Types
Affected SAP© system types

 

Related note
3312586
CVSS
4.4

Affected system type
BI/BO platform
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-39440] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform

 

Related note
3341599
CVSS
7.8

Affected system type
SAP PowerDesigner
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-36923] Code Injection vulnerability in SAP PowerDesigner

 

Related note
3337797
CVSS
7.1

Affected system type
SAP Business One
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-33993] SQL Injection vulnerability in SAP Business One (B1i Layer)

 

Related note
3358300
CVSS
7.6

Affected system type
SAP Business One
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-39437] Cross-Site Scripting (XSS) vulnerability in SAP Business One

 

Related note
3341460
CVSS
9.8

Affected system type
SAP PowerDesigner
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37483] Multiple Vulnerabilities in SAP PowerDesigner

 

Related note
3341934
CVSS
5.9

Affected system type
SAP Commerce Cloud
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37486] Information Disclosure vulnerability in SAP Commerce (OCC API)

 

Related note
3312047
CVSS
7.5

Affected system type
BI/BO platform
Patchday
2023-08
Released on
2023/08/08

Description
Denial of Service (DoS) vulnerability due to the usage of vulnerable version of Commons FileUpload in SAP BusinessObjects Business Intelligence Platform (CMC)

 

Related note
3358328
CVSS
3.7

Affected system type
SAP Host Agent
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-36926] Information disclosure vulnerability in SAP Host Agent

 

Related note
3149794
CVSS
6.1

Affected system type
SAP UI5
Patchday
2023-08
Released on
2023/08/08

Description
Cross-Site Scripting (XSS) vulnerabilities in jQuery-UI library bundled with SAPUI5

 

Related note
3156972
CVSS
6.1

Affected system type
ABAP
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-40306] URL Redirection vulnerability in SAP S/4HANA (Manage Catalog Items and Cross-Catalog search)

 

Related note
3348000
CVSS
4.9

Affected system type
ABAP
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37492] Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3346500
CVSS
8.8

Affected system type
SAP Commerce Cloud
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-39439] Improper authentication in SAP Commerce Cloud

 

Related note
3333616
CVSS
5.3

Affected system type
SAP Business One
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37487] Security Misconfiguration vulnerability in SAP Business One (Service Layer)

 

Related note
3350297
CVSS
9.1

Affected system type
ABAP
Patchday
2023-08
Released on
2023/07/11

Description
[CVE-2023-36922] OS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)

 

Related note
3344295
CVSS
7.5

Affected system type
Kernel
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37491] Improper Authorization check vulnerability in SAP Message Server

 

Related note
3350494
CVSS
6.1

Affected system type
Java
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37488] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Process Integration

 

Related note
3317710
CVSS
7.6

Affected system type
BI/BO platform
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37490] Binary hijack in SAP BusinessObjects Business Intelligence Suite (installer)

 

Related note
2032723
CVSS
6.3

Affected system type
ABAP
Patchday
2023-08
Released on
2014/11/11

Description
Switchable authorization checks for RFC in SRM

 

Related note
2067220
CVSS
5.8

Affected system type
ABAP
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-39436] Information Disclosure in SAP Supplier Relationship Management

 

 
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2024 by SecurityBridge GmbH

v34.3