Security Advisories  

We've created the first of its kind, SecurityBridge Cloud Platform to prioritize SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. Our security advisories enable SAP users to understand the security and business implications of running SAP.

The user interface, is designed to be as intuitive as possible but we'd love to hear your feedback and opinions.
We hope you like it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 113 and the highest CVSS score is 10.0.

 

 Severity
SAP© Security advisories 113
 System Types
Affected SAP© system types

 

Related note
3433192
CVSS
9.1

Affected system type
Java
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-22127] Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)

 

Related note
3425274
CVSS
9.4

Affected system type
SAP Build Apps
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2019-10744] Code Injection vulnerability in applications built with SAP Build Apps

 

Related note
3420923
CVSS
9.1

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22131] Code Injection vulnerability in SAP ABA (Application Basis)

 

Related note
3412456
CVSS
9.1

Affected system type
BTP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA

 

Related note
3413475
CVSS
9.1

Affected system type
SAP Edge Integration
Patchday
2024-01
Released on
2024/01/09

Description
[Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell

 

Related note
3399691
CVSS
9.1

Affected system type
ABAP
Patchday
2023-12
Released on
2023/12/12

Description
Update 1 to 3350297 - [CVE-2023-36922] OS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)

 

Related note
3411067
CVSS
9.1

Affected system type
BTP
Patchday
2023-12
Released on
2023/12/12

Description
[Multiple CVEs] Escalation of Privileges in SAP Business Technology Platform (BTP) Security Services Integration Libraries

 

Related note
3355658
CVSS
9.6

Affected system type
SAP Business One
Patchday
2023-11
Released on
2023/11/14

Description
[CVE-2023-31403] Improper Access Control vulnerability in SAP Business One product installation

 

Related note
3340576
CVSS
9.8

Affected system type
Kernel, HANA...
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40309] Missing Authorization check in SAP CommonCryptoLib

 

Related note
3320355
CVSS
9.9

Affected system type
SAP BI
Patchday
2023-09
Released on
2023/09/12

Description
[CVE-2023-40622] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management)

 

Related note
3350297
CVSS
9.1

Affected system type
ABAP
Patchday
2023-08
Released on
2023/07/11

Description
[CVE-2023-36922] OS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)

 

Related note
3341460
CVSS
9.8

Affected system type
SAP PowerDesigner
Patchday
2023-08
Released on
2023/08/08

Description
[CVE-2023-37483] Multiple Vulnerabilities in SAP PowerDesigner

 

Related note
3328495
CVSS
9.8

Affected system type
Reprise License Manager
Patchday
2023-05
Released on
2023/05/09

Description
Multiple vulnerabilities associated with Reprise License Manager 14.2 component used with SAP 3D Visual Enterprise License Manager

 

Related note
3307833
CVSS
9.1

Affected system type
BI/BO platform
Patchday
2023-05
Released on
2023/05/09

Description
[CVE-2023-28762] Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Console)

 

Related note
3298961
CVSS
9.8

Affected system type
BI/BO platform
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-28765] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management )

 

Related note
3305369
CVSS
10.0

Affected system type
Java
Patchday
2023-04
Released on
2023/04/11

Description
[CVE-2023-27497] Multiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge and EventLogServiceCollector)

 

Related note
3283438
CVSS
9.0

Affected system type
BI/BO platform
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-25617] OS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform (Adaptive Job Server)

 

Related note
3245526
CVSS
9.9

Affected system type
BI/BO platform
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-25616] Code Injection vulnerability in SAP Business Objects Business Intelligence Platform (CMC)

 

Related note
3302162
CVSS
9.6

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27500] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3294595
CVSS
9.6

Affected system type
ABAP
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-27269] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3252433
CVSS
9.9

Affected system type
Java
Patchday
2023-03
Released on
2023/03/14

Description
[CVE-2023-23857] Improper Access Control in SAP NetWeaver AS for Java

 

Related note
3262810
CVSS
9.9

Affected system type
BI/BO platform
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0022] Code Injection vulnerability in SAP BusinessObjects Business Intelligence platform (Analysis edition for OLAP)

 

Related note
3089413
CVSS
9.0

Affected system type
Kernel / ABAP
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0014] Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

 

Related note
3268093
CVSS
9.4

Affected system type
Java
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0017] Improper access control in SAP NetWeaver AS for Java

 

Related note
3275391
CVSS
9.9

Affected system type
SAP Business Planning...
Patchday
2023-01
Released on
2023/01/10

Description
[CVE-2023-0016] SQL Injection vulnerability in SAP Business Planning and Consolidation MS

 

Related note
3273480
CVSS
9.9

Affected system type
Java
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41272] Improper access control in SAP NetWeaver AS Java (User Defined Search)

 

Related note
3271523
CVSS
9.8

Affected system type
SAP Commerce
Patchday
2022-12
Released on
2022/12/13

Description
Remote Code Execution vulnerability associated with Apache Commons Text in SAP Commerce

 

Related note
3239475
CVSS
9.9

Affected system type
BI/BO platform
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41267] Server-Side Request Forgery vulnerability in SAP BusinessObjects Business Intelligence Platform

 

Related note
3267780
CVSS
9.4

Affected system type
Java
Patchday
2022-12
Released on
2022/12/13

Description
[CVE-2022-41271] Improper access control in SAP NetWeaver AS Java (Messaging System)

 

Related note
3243924
CVSS
9.9

Affected system type
BI/BO platform
Exploit available
Patchday
2022-11
Released on
2022/11/08

Description
[CVE-2022-41203] Insecure Deserialization of Untrusted Data in SAP BusinessObjects Business Intelligence Platform (Central Management Console and BI Launchpad)

 

Related note
3242933
CVSS
9.9

Affected system type
Java
Patchday
2022-10
Released on
2022/10/11

Description
[CVE-2022-39802] File path traversal vulnerability in SAP Manufacturing Execution

 

Related note
3189409
CVSS
9.8

Affected system type
SAP Business One Cloud
Patchday
2022-05
Released on
2022/05/10

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in in SAP Business One Cloud

 

Related note
3170990
CVSS
9.8

Affected system type
Any
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-22965] Central Security Note for Remote Code Execution vulnerability associated with Spring Framework

 

Related note
3189428
CVSS
9.8

Affected system type
SAP HANA Platform
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP HANA Extended Application Services

 

Related note
3187290
CVSS
9.8

Affected system type
SAP Customer Checkout
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Checkout

 

Related note
3189429
CVSS
9.8

Affected system type
Java
Patchday
2022-04
Released on
2022/04/12

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in PowerDesigner Web (up to including 16.7 SP05 PL01)

 

Related note
3171258
CVSS
9.8

Affected system type
SAP Commerce
Patchday
2022-04
Released on
2022/04/18

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Commerce

 

Related note
3158613
CVSS
9.1

Affected system type
Java
Patchday
2022-04
Released on
2022/04/12

Description
Update 1 to Security Note 3022622 - [CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence

 

Related note
3189635
CVSS
9.8

Affected system type
SAP Customer...
Patchday
2022-04
Released on
2022/04/14

Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Profitability Analytics

 

Related note
3145987
CVSS
9.3

Affected system type
SAP Solution Manager...
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2022-24396] Missing Authentication check in SAP Focused Run (Simple Diagnostics Agent 1.0)

 

Related note
3154684
CVSS
10.0

Affected system type
SAP Work Manager
Patchday
2022-03
Released on
2022/03/08

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Work Manager

 

Related note
3130920
CVSS
10.0

Affected system type
SAP Data Intelligence
Patchday
2022-02
Released on
2022/01/18

Description
Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Data Intelligence 3 (on-premise)

 

Related note
3139893
CVSS
10.0

Affected system type
None
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Dynamic Authorization Management

 

Related note
3123396
CVSS
10.0

Affected system type
Kernel
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22536] Request smuggling and request concatenation in SAP NetWeaver, SAP Content Server and SAP Web Dispatcher

 

Related note
3142773
CVSS
10.0

Affected system type
SAP Commerce
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Commerce

 

Related note
3140940
CVSS
9.1

Affected system type
Java
Patchday
2022-02
Released on
2022/02/08

Description
[CVE-2022-22544] Missing segregation of duties in SAP Solution Manager Diagnostics Root Cause Analysis Tools

 

Related note
3131740
CVSS
9.8

Affected system type
SAP Business One
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Business One

 

Related note
3136988
CVSS
10.0

Affected system type
SAP IoT
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Reference Template for enabling ingestion and persistence of time series data in Azure

 

Related note
3134139
CVSS
10.0

Affected system type
SAP Enterprise...
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j2 component used in SAP Enterprise Continuous Testing by Tricentis

 

Related note
3132177
CVSS
10.0

Affected system type
SAP Localization Hub
Patchday
2022-01
Released on
2021/12/22

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Localization Hub, digital compliance service for India

 

Related note
3132515
CVSS
10.0

Affected system type
SAP Edge Services 
Patchday
2022-01
Released on
2021/12/30

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services Cloud Edition

 

Related note
3132058
CVSS
10.0

Affected system type
SAP IoT
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Cloud-to-Cloud Interoperability

 

Related note
3136094
CVSS
10.0

Affected system type
SAP Digital...
Patchday
2022-01
Released on
2022/01/11

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Digital Manufacturing Cloud for Edge Computing

 

Related note
3132744
CVSS
10.0

Affected system type
SAP BTP Kyma runtime
Patchday
2021-12
Released on
2021/12/21

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Kyma

 

Related note
3109577
CVSS
9.9

Affected system type
SAP Commerce
Patchday
2021-12
Released on
2021/12/14

Description
Code Execution vulnerability in SAP Commerce, localization for China

 

Related note
3130521
CVSS
9.9

Affected system type
Java
Patchday
2021-12
Released on
2021/12/16

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration

 

Related note
3119365
CVSS
9.9

Affected system type
ABAP
Patchday
2021-12
Released on
2021/12/14

Description
[CVE-2021-44231] Code Injection vulnerability in SAP ABAP Server & ABAP Platform (Translation Tools)

 

Related note
3131397
CVSS
10.0

Affected system type
SAP HANA Platform
Patchday
2021-12
Released on
2021/12/17

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit

 

Related note
3131258
CVSS
10.0

Affected system type
SAP HANA Platform
Patchday
2021-12
Released on
2021/12/16

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP HANA XSA

 

Related note
3133772
CVSS
10.0

Affected system type
SAP Customer Checkout
Patchday
2021-12
Released on
2021/12/22

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Customer Checkout

 

Related note
3130578
CVSS
10.0

Affected system type
SAP BTP Cloud Foundry runtime
Patchday
2021-12
Released on
2021/12/21

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Cloud Foundry

 

Related note
3132909
CVSS
10.0

Affected system type
SAP Edge Services 
Patchday
2021-12
Released on
2021/12/24

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services On Premise Edition

 

Related note
3132198
CVSS
9.8

Affected system type
SAP Landscape...
Patchday
2021-12
Released on
2021/12/20

Description
[CVE-2019-17571] Code Injection vulnerability in SAP Landscape Management

 

Related note
3132822
CVSS
9.0

Affected system type
SAP HANA Platform
Patchday
2021-12
Released on
2021/12/21

Description
Update 1 to Security Note 3131397 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit

 

Related note
3132922
CVSS
10.0

Affected system type
SAP Edge Services 
Patchday
2021-12
Released on
2021/12/21

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Internet of Things Edge Platform

 

Related note
3132162
CVSS
10.0

Affected system type
SAP API Management
Patchday
2021-12
Released on
2021/12/24

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP API Management (Tenant Cloning Tool)

 

Related note
3132964
CVSS
10.0

Affected system type
SAP Enable Now
Patchday
2021-12
Released on
2021/12/23

Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Enable Now Manager

 

Related note
3131047
CVSS
10.0

Affected system type
Any
Patchday
2021-12
Released on
2021/12/15

Description
[CVE-2021-44228] Central Security Note for Remote Code Execution vulnerability associated with Apache Log4j 2 component

 

Related note
3099776
CVSS
9.6

Affected system type
Kernel
Patchday
2021-11
Released on
2021/11/09

Description
[CVE-2021-40501] Missing Authorization check in ABAP Platform Kernel

 

Related note
3097887
CVSS
9.1

Affected system type
ABAP
Patchday
2021-10
Released on
2021/10/12

Description
[CVE-2021-38178] Improper Authorization in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3101406
CVSS
9.8

Affected system type
Java
Patchday
2021-10
Released on
2021/10/12

Description
Potential XML External Entity Injection Vulnerability in SAP Environmental Compliance

 

Related note
3089438
CVSS
9.1

Affected system type
ABAP
Patchday
2021-10
Released on
2021/09/20

Description
Missing transaction start (AU3) entries in the Security Audit Log

 

Related note
3073891
CVSS
9.6

Affected system type
BCM platform
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-33672] Multiple vulnerabilities in SAP Contact Center

 

Related note
3081888
CVSS
9.9

Affected system type
Java
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-37531] Code Injection vulnerability in SAP NetWeaver Knowledge Management (XMLForms)

 

Related note
3084487
CVSS
9.9

Affected system type
Java
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38163] Unrestricted File Upload vulnerability in SAP NetWeaver (Visual Composer 7.0 RT)

 

Related note
3078609
CVSS
10.0

Affected system type
Java
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-37535] Missing Authorization check in SAP NetWeaver Application Server for Java (JMS Connector Service)

 

Related note
3089831
CVSS
9.9

Affected system type
ABAP
Patchday
2021-09
Released on
2021/09/14

Description
[CVE-2021-38176] SQL Injection vulnerability in SAP NZDT Mapping Table Framework

 

Related note
3072955
CVSS
9.9

Affected system type
Java
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33690] Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure (Component Build Service)

 

Related note
3071984
CVSS
9.9

Affected system type
SAP Business One
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33698] Unrestricted File Upload vulnerability in SAP Business One

 

Related note
3078312
CVSS
9.1

Affected system type
ABAP
Patchday
2021-08
Released on
2021/08/10

Description
[CVE-2021-33701] SQL Injection vulnerability in SAP NZDT Row Count Reconciliation

 

Related note
3007182
CVSS
9.0

Affected system type
ABAP
Patchday
2021-07
Released on
2021/06/08

Description
[CVE-2021-27610] Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform

 

Related note
3040210
CVSS
9.9

Affected system type
SAP Commerce / SAP...
Patchday
2021-04
Released on
2021/04/13

Description
[CVE-2021-27602] Remote Code Execution vulnerability in Source Rules of SAP Commerce

 

Related note
3022422
CVSS
9.6

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21481] Missing Authorization Check in SAP NetWeaver AS JAVA (MigrationService)

 

Related note
3022622
CVSS
9.9

Affected system type
Java
Patchday
2021-03
Released on
2021/03/09

Description
[CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence

 

Related note
3014121
CVSS
9.9

Affected system type
SAP Commerce Cloud
Patchday
2021-02
Released on
2021/02/09

Description
[CVE-2021-21477] Remote Code Execution vulnerability in SAP Commerce

 

Related note
2986980
CVSS
9.9

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21465] Multiple vulnerabilities in SAP Business Warehouse (Database Interface)

 

Related note
2999854
CVSS
9.9

Affected system type
ABAP
Patchday
2021-01
Released on
2021/01/12

Description
[CVE-2021-21466] Code Injection in SAP Business Warehouse and SAP BW/4HANA

 

Related note
2983367
CVSS
9.1

Affected system type
ABAP
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26838] Code Injection vulnerability in SAP Business Warehouse (Master Data Management) and SAP BW4HANA

 

Related note
2974774
CVSS
10.0

Affected system type
Java
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26829] Missing Authentication Check in SAP NetWeaver AS JAVA (P2P Cluster Communication)

 

Related note
2989075
CVSS
9.6

Affected system type
BI/BO platform
Patchday
2020-12
Released on
2020/12/08

Description
[CVE-2020-26831] Missing XML Validation in SAP BusinessObjects Business Intelligence Platform (Crystal Report)

 

Related note
2973735
CVSS
9.1

Affected system type
ABAP
Patchday
2020-11
Released on
2020/11/11

Description
[CVE-2020-26808] Code Injection in SAP AS ABAP and S/4 HANA (DMIS)

 

Related note
2979062
CVSS
9.1

Affected system type
Java
Patchday
2020-11
Released on
2020/11/10

Description
[CVE-2020-26820] Privilege escalation in SAP NetWeaver Application Server for Java (UDDI Server)

 

Related note
2985866
CVSS
10.0

Affected system type
Java
Patchday
2020-11
Released on
2020/11/10

Description
[Multiple CVE IDs] Missing Authentication Check in SAP Solution Manager (JAVA stack)

 

Related note
2982840
CVSS
9.8

Affected system type
SAP Data Services
Patchday
2020-11
Released on
2020/11/10

Description
Multiple Vulnerabilities in SAP Data Services

 

Related note
2969828
CVSS
10.0

Affected system type
Solution Manager
Patchday
2020-10
Released on
2020/10/13

Description
[CVE-2020-6364] OS Command Injection Vulnerability in CA Introscope Enterprise Manager (Affected Products: SAP Solution Manager and SAP Focused Run)

 

Related note
2961991
CVSS
9.6

Affected system type
SAP Marketing
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6320] Improper Access Control in SAP Marketing (Mobile Channel Servlet)

 

Related note
2958563
CVSS
9.1

Affected system type
ABAP
Patchday
2020-09
Released on
2020/09/08

Description
[CVE-2020-6318] Code Injection vulnerability in SAP NetWeaver (ABAP Server) and ABAP Platform

 

Related note
2928635
CVSS
9.0

Affected system type
Java
Patchday
2020-08
Released on
2020/08/11

Description
[CVE-2020-6284] Cross-Site Scripting (XSS) in SAP NetWeaver (Knowledge Management)

 

Related note
2934135
CVSS
10.0

Affected system type
Java
Exploit available
Patchday
2020-07
Released on
2020/07/14

Description
[CVE-2020-6287] Multiple Vulnerabilities in SAP NetWeaver AS JAVA (LM Configuration Wizard)

 

Related note
2918924
CVSS
9.8

Affected system type
SAP Cloud Commerce
Patchday
2020-06
Released on
2020/06/09

Description
[CVE-2020-6265] Use of Hard-coded Credentials in SAP Commerce and SAP Commerce Datahub

 

Related note
2928570
CVSS
9.8

Affected system type
Java
Patchday
2020-06
Released on
2020/06/09

Description
Ghostcat' Apache Tomcat AJP Vulnerability in SAP Liquidity Management for Banking

 

Related note
2917090
CVSS
9.0

Affected system type
SAP Adaptive Server...
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6252] Information Disclosure in SAP Adaptive Server Enterprise (Cockpit)

 

Related note
2835979
CVSS
9.9

Affected system type
ABAP
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6262] Code Injection vulnerability in Service Data Download

 

Related note
2917275
CVSS
9.1

Affected system type
SAP Adaptive Server...
Patchday
2020-05
Released on
2020/05/12

Description
[CVE-2020-6248] Code injection in SAP Adaptive Server Enterprise (Backup Server)

 

Related note
2863731
CVSS
9.1

Affected system type
BI/BO platform
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6219] Deserialization of Untrusted Data in SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer)

 

Related note
2900118
CVSS
9.1

Affected system type
SAP Orient DB
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6230] Code Injection vulnerability in SAP OrientDB 3.0

 

Related note
2904480
CVSS
9.3

Affected system type
SAP Commerce Cloud
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6238] Missing XML Validation vulnerability in SAP Commerce

 

Related note
2896682
CVSS
9.1

Affected system type
Java
Patchday
2020-04
Released on
2020/04/14

Description
[CVE-2020-6225] Directory Traversal vulnerability in SAP NetWeaver (Knowledge Management)

 

Related note
2845377
CVSS
9.8

Affected system type
Java
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6198] Missing Authentication check in SAP Solution Manager (Diagnostics Agent)

 

Related note
2806198
CVSS
9.1

Affected system type
Java
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6203] Path Manipulation in SAP NetWeaver UDDI Server(Services Registry)

 

Related note
2890213
CVSS
10.0

Affected system type
Java
Exploit available
Patchday
2020-03
Released on
2020/03/10

Description
[CVE-2020-6207] Missing Authentication Check in SAP Solution Manager (User-Experience Monitoring)

 

Related note
2622660
CVSS
10.0

Affected system type
SAP GUI / Frontend
Patchday
2020-02
Released on
2018/04/10

Description
Security updates for the browser control Google Chromium delivered with SAP Business Client

 

Related note
2839864
CVSS
9.1

Affected system type
Java
Patchday
2019-11
Released on
2019/11/12

Description
Update 2 to Security Note 2808158: [CVE-2019-0330] OS Command Injection vulnerability in SAP Diagnostics Agent

 

 
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2024 by SecurityBridge GmbH

v34.3