We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.
We hope you enjoy using it!
This time we found critical correction advisiories. We count 18 and the highest CVSS score is 9.8.
Severity
SAP© Security advisories 18
System Types
Affected SAP© system types
Affected system
type
ABAP
Patchday
2020-06
Released
on
2020/06/09
Description
[CVE-2020-6270] Missing Authorization check in SAP Netweaver AS ABAP (Banking Services)
Affected system
type
ABAP
Patchday
2020-06
Released
on
2020/06/09
Description
Switchable Authorization checks for RFC in Environment, Health & Safety
Affected system
type
Adobe LiveCycle Designer
Patchday
2020-06
Released
on
2020/06/09
Description
Multiple vulnerabilities in Adobe LiveCycle Designer 11.0
Affected system
type
SAP Cloud Commerce
Patchday
2020-06
Released
on
2020/06/09
Description
[CVE-2020-6265] Use of Hard-coded Credentials in SAP Commerce and SAP Commerce Datahub
Affected system
type
SAP Business One
Patchday
2020-06
Released
on
2020/06/09
Description
[CVE-2020-6239] Information Disclosure in SAP Business One (Backup Service)
Affected system
type
ABAP
Patchday
2020-06
Released
on
2020/06/09
Description
Update 1 to Security Note 2752614 - [CVE-2019-0319] Content Injection Vulnerability in SAP Gateway
Affected system
type
ABAP
Patchday
2020-06
Released
on
2020/06/09
Description
[CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA
Affected system
type
BI/BO platform
Patchday
2020-06
Released
on
2020/06/09
Description
[CVE-2020-6269] Information Disclosure in SAP Business Objects Business Intelligence Platform
Affected system
type
ABAP
Patchday
2020-06
Released
on
2020/06/09
Description
[CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA
Affected system
type
Java
Patchday
2020-06
Released
on
2020/06/09
Description
[CVE-2020-6260] Incomplete XML Validation in SAP Solution Manager (Trace Analysis)
Affected system
type
SAP Cloud Commerce
Patchday
2020-06
Released
on
2020/06/09
Description
[CVE-2020-6264] Information Disclosure in SAP Commerce
Affected system
type
ABAP
Patchday
2020-06
Released
on
2020/06/09
Description
[CVE-2020-6268] Missing authorization check in SAP ERP (Statutory Reporting for Insurance Companies)
Affected system
type
ABAP
Patchday
2020-06
Released
on
2020/06/09
Description
Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI
Affected system
type
Java
Patchday
2020-06
Released
on
2020/06/09
Description
[CVE-2020-6271] Missing XML Validation in SAP Solution Manager (Problem Context Manager)
Affected system
type
Java
Patchday
2020-06
Released
on
2020/06/09
Description
Ghostcat' Apache Tomcat AJP Vulnerability in SAP Liquidity Management for Banking
Affected system
type
Java
Patchday
2020-06
Released
on
2020/06/09
Description
[CVE-2020-6263] Authentication Bypass in Standalone Clients connecting to SAP NetWeaver AS Java via P4 Protocol
Affected system
type
ABAP
Patchday
2020-06
Released
on
2020/06/09
Description
[CVE-2020-6275] Server Side Request Forgery vulnerability in SAP NetWeaver AS ABAP
Affected system
type
ABAP
Patchday
2020-06
Released
on
2020/06/09
Description
[CVE-2020-6246] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP ( Business Server Pages Test Application SBSPEXT_TABLE)