We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.
We hope you enjoy using it!
This time we found critical correction advisiories. We count 20 and the highest CVSS score is 10.0.
Severity
SAP© Security advisories 20
System Types
Affected SAP© system types
Affected system
type
ABAP
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6205] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP Business Server Pages (Smart Forms)
Affected system
type
ABAP
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6199] Missing Authorization check in SAP ERP and S/4 HANA (MENA Certificate Management)
Affected system
type
SAP Enable Now
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6178] Insufficient session expiration in SAP Enable Now Manager
Affected system
type
ABAP
Patchday
2020-03
Released
on
2020/03/10
Description
Missing Authorization check in Commercial Project Management
Affected system
type
Java
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6203] Path Manipulation in SAP NetWeaver UDDI Server(Services Registry)
Affected system
type
Java
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6202] Missing XML Validation in SAP NetWeaver Application Server Java (User Management Engine)
Affected system
type
ABAP
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6210] Cross-Site Scripting (XSS) vulnerability in SAP Fiori Launchpad
Affected system
type
ABAP
Patchday
2020-03
Released
on
2020/03/10
Description
Directory traversal in SAP Environment Health and Safety
Affected system
type
SAP Commerce Cloud
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6200] Cross-Site-Scripting in SAP Commerce Cloud (SmartEdit extension)
Affected system
type
SAP Commerce Cloud
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6201] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Cloud (testweb extension)
Affected system
type
ABAP Development Tools
Patchday
2020-03
Released
on
2020/03/10
Description
Missing XML Validation vulnerability in ABAP Development Tools
Affected system
type
Java
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6198] Missing Authentication check in SAP Solution Manager (Diagnostics Agent)
Affected system
type
BI/BO platform
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6196] Denial of service (DOS) in SAP BusinessObjects Mobile (MobileBIService)
Affected system
type
ABAP
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6204] Missing Authorization check in SAP Treasury and Risk Management (Transaction Management)
Affected system
type
SAP Enable Now
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6197] Insufficient session expiration in SAP Enable Now Manager
Affected system
type
SAP Disclosure Management
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6209] Missing Authorization check in SAP Disclosure Management
Affected system
type
SAP CPI DS
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6206] Cross-Site Request Forgery in SAP Cloud Platform Integration for data services
Affected system
type
Java
Exploit available
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6207] Missing Authentication Check in SAP Solution Manager (User-Experience Monitoring)
Affected system
type
SAP MaxDB
Patchday
2020-03
Released
on
2018/08/14
Description
[CVE-2018-2450] SQL Injection Vulnerability in SAP MaxDB/liveCache
Affected system
type
BI/BO platform
Patchday
2020-03
Released
on
2020/03/10
Description
[CVE-2020-6208] Remote Code Execution in SAP Business Objects Business Intelligence Platform (Crystal Reports)