Security Advisories
We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.
We hope you like it!
This time we found critical correction advisiories. We count 33 and the highest CVSS score is 9.4.
Severity
SAP© Security advisories 33
System Types
Affected SAP© system types
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-25644] Information Disclosure vulnerability in SAP NetWeaver (WSRM)
Affected system
type
BI/BO platform
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2023-50164] Path Traversal Vulnerability in SAP BusinessObjects Business Intelligence Platform (Central Management Console)
Affected system
type
Kernel
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-27902] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP, applications based on SAPGUI for HTML (WebGUI)
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-25645] Information Disclosure vulnerability in SAP NetWeaver (Enterprise Portal)
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-28163] Information Disclosure vulnerability in SAP NetWeaver Process Integration (Support Web Pages)
Affected system
type
ABAP
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-27900]Missing Authorization check in SAP ABAP Platform
Affected system
type
ABAP
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-22133] Improper Access Control in SAP Fiori Front End Server
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-22127] Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)
Affected system
type
HANA platform
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2023-44487 ] Denial of service (DOS) in SAP HANA XS Classic and HANA XS Advanced
Affected system
type
SAP Build Apps
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2019-10744] Code Injection vulnerability in applications built with SAP Build Apps
Affected system
type
Java
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24743] XXE vulnerability in SAP NetWeaver AS Java (Guided Procedures)
Affected system
type
SAP Enable Now
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22129] Cross-Site Scripting (XSS) vulnerability in SAP Companion
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24739] Missing authorization check in SAP Bank Account Management
Affected system
type
SAP Cloud Connector
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-25642] Improper Certificate Validation in SAP Cloud Connector
Affected system
type
Java
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application)
Affected system
type
Kernel
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24740] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (SAP Kernel)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22132] Code Injection vulnerability in SAP IDES Systems
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22128] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Business Client for HTML
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-25643] Missing authorization check in SAP Fiori app ("My Overtime Requests")
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22130] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/01
Description
[CVE-2024-24741] Missing Authorization check in SAP Master Data Governance Material
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22131] Code Injection vulnerability in SAP ABA (Application Basis)
Affected system
type
SAP Edge Integration
Patchday
2024-01
Released
on
2024/01/09
Description
[Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell
Affected system
type
SAP GUI / Frontend
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-22125] Information Disclosure vulnerability in Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge)
Affected system
type
Kernel
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2023-44487] Denial of service (DOS) in SAP Web Dispatcher, SAP NetWeaver Application server ABAP, and ABAP Platform
Affected system
type
BTP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA
Affected system
type
SAP Marketing
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21734] URL Redirection vulnerability in SAP Marketing (Contacts App)
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21738] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21735] Improper Authorization check in SAP LT Replication Server
Affected system
type
Kernel / Web Dispatcher
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-22124] Information Disclosure vulnerability in SAP NetWeaver Internet Communication Manager
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21736] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21737] Code Injection vulnerability in SAP Application Interface Framework (File Adapter)