We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.
We hope you like it!
This time we found critical correction advisiories. We count 82 and the highest CVSS score is 9.8.
Severity
SAP© Security advisories 82
System Types
Affected SAP© system types
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39592] Missing Authorization check in SAP PDCE
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34689] Server-Side Request Forgery in SAP Business Workflow (WebFlow Services)
Affected system
type
SAP Commerce
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39597] Improper Authorization Checks on Early Login Composable Storefront B2B sites of SAP Commerce
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34689] Allowlisting of callback-URLs in SAP Business Workflow (WebFlow Services)
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39594] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Business Warehouse - Business Planning and Simulation
Affected system
type
SAP Enable Now
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34692] Unrestricted File upload vulnerability in SAP Enable Now
Affected system
type
SAP CRM UI
Patchday
2024-07
Released
on
2024/07/09
Description
[Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI)
Affected system
type
Java
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34685] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Knowledge Management XMLEditor
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34689] Prerequisite for Security Note 3458789
Affected system
type
SAP GUI
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39600] Information Disclosure vulnerability in SAP GUI for Windows
Affected system
type
SAP Landscape...
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39593] Information Disclosure vulnerability in SAP Landscape Management
Affected system
type
SAP Enable Now
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39596] Missing Authorization check vulnerability in SAP Enable Now
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39599] Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-37171] Server-Side Request Forgery (SSRF) in SAP Transportation Management (Collaboration Portal)
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-37172] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-37176] Missing Authorization check in SAP BW/4HANA Transformation and DTP
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34690] Missing Authorization check in SAP Student Life Cycle Management (SLcM)
Affected system
type
SAP Financial Consolidation
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-37177] Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-33001] Denial of service (DOS) in SAP NetWeaver and ABAP platform
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34691] Missing Authorization check in SAP S/4HANA (Manage Incoming Payment Files)
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34686] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Affected system
type
Java
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-28164] Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures)
Affected system
type
BI/BO platform
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34684] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Scheduling)
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34683] Unrestricted file upload in SAP Document Builder (HTTP service)
Affected system
type
Java
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34688] Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[Multiple CVEs] Missing Authorization Checks in SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-34687] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application server for ABAP and ABAP Platform
Affected system
type
Sybase platform
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33008] Memory Corruption vulnerability in SAP Replication Server
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33007] Client-side script execution vulnerability in SAP UI5(PDFViewer)
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-32731] Missing Authorization check in SAP My Travel Requests
Affected system
type
SAP Commerce Cloud
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2019-17495] Multiple vulnerabilities in SAP CX Commerce
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33009] SQL injection vulnerability in SAP Global Label Management (GLM)
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-32733] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33000] Missing Authorization check in SAP Bank Account Management
Affected system
type
BI/BO platform
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33004] Insecure Storage vulnerability in SAP BusinessObjects Business Intelligence Platform (Webservices)
Affected system
type
BI/BO platform
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-28165] Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33002] Cross-Site Scripting (XSS) Vulnerability in SAP S/4HANA (Document Service Handler for DPS)
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33006] File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Affected system
type
SAP Edge Integration
Patchday
2024-04
Released
on
2024/04/09
Description
Stack overflow vulnerability on the component images of SAP Integration Suite (EDGE INTEGRATION CELL)
Affected system
type
ABAP
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-28167] Missing Authorization check in SAP Group Reporting Data Collection (Enter Package Data)
Affected system
type
Kernel
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-30218] Denial of service (DOS) vulnerability in SAP NetWeaver AS ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-30216] Missing Authorization check in SAP S/4 HANA (Cash Management)
Affected system
type
Java
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-27899] Security misconfiguration vulnerability in SAP NetWeaver AS Java User Management Engine
Affected system
type
BI/BO platform
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-25646] Information Disclosure vulnerability in SAP BusinessObjects Web Intelligence
Affected system
type
Java
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-27898] Server-Side Request Forgery in SAP NetWeaver (tc~esi~esp~grmg~wshealthcheck~ear)
Affected system
type
ABAP
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-30217] Missing Authorization check in SAP S/4 HANA (Cash Management)
Affected system
type
SAP Business Connector
Patchday
2024-04
Released
on
2024/04/09
Description
[Multiple CVEs] Cross-Site Scripting (XSS) vulnerabilities in SAP Business Connector
Affected system
type
ABAP
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-27901] Directory Traversal vulnerability in SAP Asset Accounting
Affected system
type
Kernel
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-27902] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP, applications based on SAPGUI for HTML (WebGUI)
Affected system
type
BI/BO platform
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2023-50164] Path Traversal Vulnerability in SAP BusinessObjects Business Intelligence Platform (Central Management Console)
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-25644] Information Disclosure vulnerability in SAP NetWeaver (WSRM)
Affected system
type
SAP Build Apps
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2019-10744] Code Injection vulnerability in applications built with SAP Build Apps
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-22127] Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)
Affected system
type
HANA platform
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2023-44487 ] Denial of service (DOS) in SAP HANA XS Classic and HANA XS Advanced
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-25645] Information Disclosure vulnerability in SAP NetWeaver (Enterprise Portal)
Affected system
type
ABAP
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-22133] Improper Access Control in SAP Fiori Front End Server
Affected system
type
ABAP
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-27900]Missing Authorization check in SAP ABAP Platform
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-28163] Information Disclosure vulnerability in SAP NetWeaver Process Integration (Support Web Pages)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22132] Code Injection vulnerability in SAP IDES Systems
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/01
Description
[CVE-2024-24741] Missing Authorization check in SAP Master Data Governance Material
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22131] Code Injection vulnerability in SAP ABA (Application Basis)
Affected system
type
Java
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24743] XXE vulnerability in SAP NetWeaver AS Java (Guided Procedures)
Affected system
type
SAP Enable Now
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22129] Cross-Site Scripting (XSS) vulnerability in SAP Companion
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24739] Missing authorization check in SAP Bank Account Management
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22128] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Business Client for HTML
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22130] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Affected system
type
Kernel
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24740] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (SAP Kernel)
Affected system
type
Java
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-25643] Missing authorization check in SAP Fiori app ("My Overtime Requests")
Affected system
type
SAP Cloud Connector
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-25642] Improper Certificate Validation in SAP Cloud Connector
Affected system
type
BTP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA
Affected system
type
SAP Marketing
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21734] URL Redirection vulnerability in SAP Marketing (Contacts App)
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21738] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21735] Improper Authorization check in SAP LT Replication Server
Affected system
type
Kernel / Web Dispatcher
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-22124] Information Disclosure vulnerability in SAP NetWeaver Internet Communication Manager
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21736] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21737] Code Injection vulnerability in SAP Application Interface Framework (File Adapter)
Affected system
type
SAP Edge Integration
Patchday
2024-01
Released
on
2024/01/09
Description
[Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell
Affected system
type
SAP GUI / Frontend
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-22125] Information Disclosure vulnerability in Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge)
Affected system
type
Kernel
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2023-44487] Denial of service (DOS) in SAP Web Dispatcher, SAP NetWeaver Application server ABAP, and ABAP Platform