We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.
We hope you enjoy using it!
This time we found critical correction advisiories. We count 11 and the highest CVSS score is 9.9.
Severity
SAP© Security advisories 11
System Types
Affected SAP© system types
Affected system
type
SAP IDM
Patchday
2020-05
Released
on
2020/05/12
Description
[CVE-2020-6258] Missing Authorization check in SAP Identity Management
Affected system
type
SAP Adaptive Server...
Patchday
2020-05
Released
on
2020/05/12
Description
[CVE-2020-6243] Code Injection in SAP Adaptive Server Enterprise (XP Server on Windows Platform)
Affected system
type
SAP Adaptive Server...
Patchday
2020-05
Released
on
2020/05/12
Description
[CVE-2020-6241] SQL Injection vulnerability in SAP Adaptive Server Enterprise
Affected system
type
SAP Adaptive Server...
Patchday
2020-05
Released
on
2020/05/12
Description
[CVE-2020-6250] Information Disclosure in SAP Adaptive Server Enterprise
Affected system
type
SAP Adaptive Server...
Patchday
2020-05
Released
on
2020/05/12
Description
[CVE-2020-6252] Information Disclosure in SAP Adaptive Server Enterprise (Cockpit)
Affected system
type
SAP Adaptive Server...
Patchday
2020-05
Released
on
2020/05/12
Description
[CVE-2020-6253] SQL Injection vulnerability in SAP Adaptive Server Enterprise (Web Services)
Affected system
type
SAP Adaptive Server...
Patchday
2020-05
Released
on
2020/05/12
Description
[CVE-2020-6248] Code injection in SAP Adaptive Server Enterprise (Backup Server)
Affected system
type
SAP Adaptive Server...
Patchday
2020-05
Released
on
2020/05/12
Description
[CVE-2020-6259] Missing authorization check in SAP Adaptive Server Enterprise
Affected system
type
ABAP
Patchday
2020-05
Released
on
2020/05/12
Description
[CVE-2020-6262] Code Injection vulnerability in Service Data Download
Affected system
type
SAP Enterprise Threat...
Patchday
2020-05
Released
on
2020/05/12
Description
[CVE-2020-6254] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Threat Detection
Affected system
type
ABAP
Patchday
2020-05
Released
on
2020/05/12
Description
This note has been re-released without changes. - Cross-Site Request Forgery (CSRF) vulnerability in SAP Web Dynpro ABAP