Security Advisories  

We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.

The user interface, is designed to be as intuitive as possible but we'd love to hear your feedback and opinions.
We hope you like it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 13 and the highest CVSS score is 9.9.

 

 Severity
SAP© Security advisories 13
 System Types
Affected SAP© system types

 

Related note
3349805
CVSS
5.7

Affected system type
Java
Patchday
2023-09
Released on
2023/09/12

Description
Denial of service (DOS) vulnerability due to the usage of vulnerable version of Commons File Upload in SAP Quotation Management Insurance (FS-QUO)

 

Related note
3352453
CVSS
5.3

Affected system type
BI/BO platform
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-37489] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Version Management System)

 

Related note
3326361
CVSS
5.4

Affected system type
ABAP
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40625] Missing Authorization check in Manage Purchase Contracts App

 

Related note
3323163
CVSS
5.5

Affected system type
ABAP
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40624] Code Injection vulnerability in SAP NetWeaver AS ABAP (applications based on Unified Rendering)

 

Related note
3370490
CVSS
8.7

Affected system type
BI/BO platform
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-42472] Insufficient File type validation in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)

 

Related note
3348142
CVSS
5.3

Affected system type
Java
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-41367] Missing Authentication check in SAP NetWeaver (Guided Procedures)

 

Related note
3369680
CVSS
3.5

Affected system type
ABAP
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-41369] External Entity Loop vulnerability in SAP S/4HANA (Create Single Payment application)

 

Related note
3340576
CVSS
9.8

Affected system type
Kernel, HANA...
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40309] Missing Authorization check in SAP CommonCryptoLib

 

Related note
3327896
CVSS
7.5

Affected system type
Kernel
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40308] Memory Corruption vulnerability in SAP CommonCryptoLib

 

Related note
3317702
CVSS
6.2

Affected system type
BI/BO platform
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40623] Arbitrary File Delete via Directory Junction in SAP BusinessObjects Suite(installer)

 

Related note
3357163
CVSS
6.3

Affected system type
PowerDesigner
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40621] Code Injection vulnerability in SAP PowerDesigner Client

 

Related note
3355675
CVSS
2.7

Affected system type
ABAP
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-41368] Insecure Direct Object Reference (IDOR) vulnerability in SAP S/4HANA (Manage checkbook apps)

 

Related note
3320355
CVSS
9.9

Affected system type
SAP BI
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40622] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management)

 

 
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2024 by SecurityBridge GmbH

v34.3