We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.
We hope you enjoy using it!
This time we found critical correction advisiories. We count 21 and the highest CVSS score is 10.0.
Severity
SAP© Security advisories 21
System Types
Affected SAP© system types
Affected system
type
ABAP
Patchday
2020-10
Released
on
2020/10/13
Description
Cross-Site Request Forgery (CSRF) in SAP Marketing
Affected system
type
ABAP
Patchday
2020-10
Released
on
2020/10/13
Description
Missing Authorization check in Manage Substitutions - Products and Manage Exclusions - Products
Affected system
type
SAP Commerce Cloud
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6363] Insufficient Session Expiration in SAP Commerce Cloud
Affected system
type
Java
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6319] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java
Affected system
type
ABAP
Patchday
2020-10
Released
on
2020/10/13
Description
Missing Authorization check in EHS Task Definition attachments
Affected system
type
SAP CRM UI
Patchday
2020-10
Released
on
2020/09/22
Description
Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI
Affected system
type
SAP Enterprise Portal...
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6323] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (Fiori Framework Page)
Affected system
type
ABAP
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6362] Incorrect Authorization in SAP Banking Services
Affected system
type
Solution Manager
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6364] OS Command Injection Vulnerability in CA Introscope Enterprise Manager (Affected Products: SAP Solution Manager and SAP Focused Run)
Affected system
type
BI/BO platform
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6308] Server-Side Request Forgery vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Services)
Affected system
type
ABAP
Patchday
2020-10
Released
on
2020/09/09
Description
Cross-Site Scripting (XSS) vulnerability in CRM Interaction Center
Affected system
type
Java
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6365] Reverse Tabnabbing vulnerability in SAP NetWeaver AS Java Start Page
Affected system
type
SAP Commerce Cloud
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6272] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Cloud
Affected system
type
Java
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6367] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Composite Application Framework
Affected system
type
ABAP
Patchday
2020-10
Released
on
2020/10/13
Description
Information Disclosure in Supplier Relationship Management
Affected system
type
ABAP
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6368] Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation
Affected system
type
ABAP
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6371] Information disclosure in SAP NetWeaver AS ABAP via the POWL Test Feeder endpoint
Affected system
type
Java
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6366] Missing XML Validation in SAP NetWeaver (Compare Systems)
Affected system
type
SAP 3D Visual Enterprise
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6315] Multiple Vulnerabilities in SAP 3D Visual Enterprise Viewer
Affected system
type
SAP NetWeaver...
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6370] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (DI Design Time Repository)
Affected system
type
SAP Solution Manager...
Patchday
2020-10
Released
on
2020/10/13
Description
[CVE-2020-6369] Hard-coded Credentials in CA Introscope Enterprise Manager (Affected products: SAP Solution Manager and SAP Focused Run)