We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.
We hope you enjoy using it!
This time we found critical correction advisiories. We count 179 and the highest CVSS score is 10.0.
Severity
SAP© Security advisories 179
System Types
Affected SAP© system types
Affected system
type
ABAP
Patchday
2021-12
Released
on
2021/12/14
Description
Missing Authorization Check in DIMP Industry Solution (Equipment and Tools Management & Bills of Services)
Affected system
type
SAP 3D Visual Enterprise
Patchday
2021-12
Released
on
2021/12/14
Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
Any
Patchday
2021-12
Released
on
2021/12/15
Description
[CVE-2021-44228] Central Security Note for Remote Code Execution vulnerability associated with Apache Log4j 2 component
Affected system
type
ABAP
Patchday
2021-12
Released
on
2021/12/14
Description
[CVE-2021-44231] Code Injection vulnerability in SAP ABAP Server & ABAP Platform (Translation Tools)
Affected system
type
ABAP
Patchday
2021-12
Released
on
2021/11/23
Description
Missing Authorization check in RFC enabled function modules in SRM
Affected system
type
ABAP
Patchday
2021-12
Released
on
2021/12/14
Description
[CVE-2021-44232] Directory Traversal vulnerability in SAF-T Framework
Affected system
type
ABAP
Patchday
2021-12
Released
on
2021/12/14
Description
[CVE-2021-44235] Code Injection vulnerability in utility class for SAP NetWeaver AS ABAP
Affected system
type
SAP HANA Platform
Patchday
2021-12
Released
on
2021/12/17
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit
Affected system
type
SAP HANA Platform
Patchday
2021-12
Released
on
2021/12/16
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP HANA XSA
Affected system
type
SAP Customer Checkout
Patchday
2021-12
Released
on
2021/12/22
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Customer Checkout
Affected system
type
SAP BTP Cloud Foundry runtime
Patchday
2021-12
Released
on
2021/12/21
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Cloud Foundry
Affected system
type
SAP Edge Services
Patchday
2021-12
Released
on
2021/12/24
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services On Premise Edition
Affected system
type
Java
Patchday
2021-12
Released
on
2021/12/16
Description
Update 1 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration
Affected system
type
SAP Landscape...
Patchday
2021-12
Released
on
2021/12/20
Description
[CVE-2019-17571] Code Injection vulnerability in SAP Landscape Management
Affected system
type
SAP HANA Platform
Patchday
2021-12
Released
on
2021/12/21
Description
Update 1 to Security Note 3131397 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit
Affected system
type
SAP BTP Kyma runtime
Patchday
2021-12
Released
on
2021/12/21
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Kyma
Affected system
type
SAP Cloud for Customer
Patchday
2021-12
Released
on
2021/12/23
Description
[CVE-2021-44228] Code Injection vulnerability in Cloud for Customer Lotus Notes PlugIn
Affected system
type
SAP Edge Services
Patchday
2021-12
Released
on
2021/12/21
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Internet of Things Edge Platform
Affected system
type
SAP Connected Health platform
Patchday
2021-12
Released
on
2021/12/20
Description
[CVE-2021-44228] Log4j Vulnerability in Connected Health Platform 2.0 - Fhirserver
Affected system
type
SAP Enable Now
Patchday
2021-12
Released
on
2021/12/23
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Enable Now Manager
Affected system
type
SAP Commerce
Patchday
2021-12
Released
on
2021/12/14
Description
[CVE-2021-42064] SQL Injection vulnerability in SAP Commerce
Affected system
type
SAP API Management
Patchday
2021-12
Released
on
2021/12/24
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP API Management (Tenant Cloning Tool)
Affected system
type
Java
Patchday
2021-12
Released
on
2021/12/14
Description
[CVE-2021-42063] Cross-Site Scripting (XSS) vulnerability in SAP Knowledge Warehouse
Affected system
type
SAP Commerce
Patchday
2021-12
Released
on
2021/12/14
Description
Code Execution vulnerability in SAP Commerce, localization for China
Affected system
type
SAP Commerce
Patchday
2021-12
Released
on
2021/12/14
Description
Denial of service (DOS) in SAP Commerce
Affected system
type
SAP Landscape Management
Patchday
2021-12
Released
on
2021/12/14
Description
Missing Authorization Check in SAP Landscape Management
Affected system
type
Java
Patchday
2021-12
Released
on
2021/12/16
Description
[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration
Affected system
type
ABAP
Patchday
2021-12
Released
on
2021/11/23
Description
Missing Authorization Check in Vehicle Management System
Affected system
type
BI/BO platform
Patchday
2021-12
Released
on
2021/12/14
Description
[CVE-2021-42061] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform (Web Intelligence)
Affected system
type
SAP UI5
Patchday
2021-12
Released
on
2021/12/14
Description
Cross-Site Scripting (XSS) Vulnerability in SAP Fiori Launchpad
Affected system
type
ABAP
Patchday
2021-12
Released
on
2021/12/14
Description
[CVE-2021-44233] Missing Authorization check in GRC Access Control
Affected system
type
ABAP
Patchday
2021-11
Released
on
2021/11/09
Description
[CVE-2021-40504] Leverage of Permission in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
SAP Commerce
Patchday
2021-11
Released
on
2021/11/09
Description
[CVE-2021-40502] Missing Authorization check in SAP Commerce
Affected system
type
Kernel
Patchday
2021-11
Released
on
2021/11/09
Description
[CVE-2021-40501] Missing Authorization check in ABAP Platform Kernel
Affected system
type
SAP GUI / Frontend
Patchday
2021-11
Released
on
2021/11/09
Description
[CVE-2021-40503] Information Disclosure in SAP GUI for Windows
Affected system
type
Java
Patchday
2021-11
Released
on
2021/11/09
Description
Cross-Site Request Forgery vulnerability in Enterprise Services Repository of SAP Process Integration
Affected system
type
ABAP
Patchday
2021-11
Released
on
2021/11/09
Description
URL Redirection vulnerability in Offer Management
Affected system
type
SAP FRP
Patchday
2021-11
Released
on
2021/11/09
Description
Several security vulnerabilities in FRP 5.4.0 and FR Engine 5.4.0
Affected system
type
ABAP
Patchday
2021-11
Released
on
2021/11/09
Description
[CVE-2021-42062] Missing Authorization check in SAP ERP HCM
Affected system
type
SAP Business One
Patchday
2021-10
Released
on
2021/10/12
Description
[CVE-2021-38180] CSV Injection in SAP Business One
Affected system
type
SAP UI5
Patchday
2021-10
Released
on
2021/10/12
Description
Cross-Site Scripting (XSS) vulnerability in SAPUI5
Affected system
type
ABAP
Patchday
2021-10
Released
on
2021/10/12
Description
[CVE-2021-38183] Cross-Site Scripting (XSS) vulnerability in cms Service of SAP NetWeaver
Affected system
type
ABAP
Patchday
2021-10
Released
on
2021/09/20
Description
Missing transaction start (AU3) entries in the Security Audit Log
Affected system
type
SAP Cloud Print Manager
Patchday
2021-10
Released
on
2021/10/12
Description
[CVE-2021-40499] Code Injection vulnerability for SAP NetWeaver Application Server for ABAP (SAP Cloud Print Manager and SAPSprint)
Affected system
type
SAP Success Factors
Patchday
2021-10
Released
on
2021/10/12
Description
[CVE-2021-40498] Denial of service (DOS) in the SAP SuccessFactors Mobile Application for Android devices
Affected system
type
ABAP
Patchday
2021-10
Released
on
2021/10/12
Description
[CVE-2021-38178] Improper Authorization in SAP NetWeaver AS ABAP and ABAP Platform
Affected system
type
BI/BO platform
Patchday
2021-10
Released
on
2021/10/12
Description
[CVE-2021-40497] Information Disclosure in SAP BusinessObjects Analysis (edition for OLAP)
Affected system
type
SAP Business One
Patchday
2021-10
Released
on
2021/10/12
Description
[CVE-2021-38179] Information Disclosure in SAP Business One
Affected system
type
ABAP
Patchday
2021-10
Released
on
2021/10/12
Description
Missing Authorization check in SCM BAPIs
Affected system
type
Java
Patchday
2021-10
Released
on
2021/10/12
Description
Potential XML External Entity Injection Vulnerability in SAP Environmental Compliance
Affected system
type
ABAP
Patchday
2021-10
Released
on
2021/10/12
Description
[CVE-2021-40495] Denial of Service (DOS) in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2021-10
Released
on
2021/09/28
Description
Cross-Site Request Forgery (CSRF) vulnerability for S/4HANA OP2020, OP1909 in Import Financial Plan Data
Affected system
type
ABAP
Patchday
2021-10
Released
on
2021/10/12
Description
[CVE-2021-38181] Denial of service (DOS) in SAP NetWeaver AS ABAP and ABAP Platform
Affected system
type
BI/BO platform
Patchday
2021-10
Released
on
2021/10/12
Description
[CVE-2021-40500] Missing XML Validation in SAP BusinessObjects Business Intelligence Platform (Crystal Reports)
Affected system
type
ABAP
Patchday
2021-10
Released
on
2021/10/12
Description
[CVE-2021-40496] Improper Access Control in SAP NetWeaver AS ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2021-10
Released
on
2021/09/28
Description
Cross-Site Request Forgery (CSRF) vulnerability in S/4HANA OP2020, OP1909 in Import Financial Plan Data
Affected system
type
SAP Business One
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-33688] SQL Injection vulnerability in SAP Business One
Affected system
type
Java
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-38163] Unrestricted File Upload vulnerability in SAP NetWeaver (Visual Composer 7.0 RT)
Affected system
type
ABAP
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-38176] SQL Injection vulnerability in SAP NZDT Mapping Table Framework
Affected system
type
Kernel
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-38162] HTTP Request Smuggling in SAP Web Dispatcher
Affected system
type
ABAP
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-38164] Missing Authorization check in in SAP ERP Financial Accounting / RFOPENPOSTING_FR
Affected system
type
Java
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-37531] Code Injection vulnerability in SAP NetWeaver Knowledge Management (XMLForms)
Affected system
type
Java
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-37535] Missing Authorization check in SAP NetWeaver Application Server for Java (JMS Connector Service)
Affected system
type
SAP Business One
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-33685] Directory Traversal vulnerability in SAP Business One
Affected system
type
ABAP Java HANA platform
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-38177] Null Pointer Dereference vulnerability in SAP CommonCryptoLib
Affected system
type
Java
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-21489] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
ABAP
Patchday
2021-09
Released
on
2021/09/14
Description
Missing Authorization check in Financial Accounting
Affected system
type
ABAP
Patchday
2021-09
Released
on
2021/09/14
Description
Reverse tabnabbing vulnerability in SAP Marketing Lead Nurture Stream
Affected system
type
SAP Business One
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-33686] Information Disclosure in SAP Business One
Affected system
type
ABAP
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-38175] Information Disclosure in SAP Analysis for Microsoft Office
Affected system
type
SAP Business One
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-37532] Directory Listing Enabled in SAP Business One
Affected system
type
BCM platform
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-33672] Multiple vulnerabilities in SAP Contact Center
Affected system
type
SAP GUI / Frontend
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-38150] Information disclosure in SAP Business Client
Affected system
type
SAP 3D Visual Enterprise
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-38174] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
BI/BO platform
Patchday
2021-09
Released
on
2021/09/14
Description
[CVE-2021-33679] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI Workspace)
Affected system
type
BI/BO platform
Patchday
2021-08
Released
on
2021/08/10
Description
[CVE-2021-33696] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Crystal Report)
Affected system
type
Java
Patchday
2021-08
Released
on
2021/08/10
Description
[CVE-2021-33703] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
ABAP
Patchday
2021-08
Released
on
2021/07/27
Description
Cross-Site Scripting (XSS) Vulnerability in BSP application CRM_CM
Affected system
type
SAP Business One
Patchday
2021-08
Released
on
2021/08/10
Description
[CVE-2021-33700] Missing Authentication check in SAP Business One
Affected system
type
Java
Patchday
2021-08
Released
on
2021/08/10
Description
[CVE-2021-33707] URL Redirection vulnerability in SAP NetWeaver (Knowledge Management)
Affected system
type
SAP Cloud Connector
Patchday
2021-08
Released
on
2021/08/10
Description
[CVE-2021-33695] Multiple Vulnerabilities in SAP Cloud Connector
Affected system
type
BI/BO platform
Patchday
2021-08
Released
on
2021/08/10
Description
[CVE-2021-33697] Reverse Tabnabbing in SAP BusinessObjects Business Intelligence Platform (SAP UI5)
Affected system
type
SAP Fiori Client Android
Patchday
2021-08
Released
on
2021/08/10
Description
[CVE-2021-33699] Task Hijacking in SAP Fiori Client Native Mobile for Android
Affected system
type
Java
Patchday
2021-08
Released
on
2021/08/10
Description
[CVE-2021-33705] Server-Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
SAP Business One
Patchday
2021-08
Released
on
2021/08/10
Description
[CVE-2021-33698] Unrestricted File Upload vulnerability in SAP Business One
Affected system
type
Kernel
Patchday
2021-08
Released
on
2021/08/10
Description
Missing Authentication check in SAP Web Dispatcher
Affected system
type
Java
Patchday
2021-08
Released
on
2021/08/10
Description
[CVE-2021-33702] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
Java
Patchday
2021-08
Released
on
2021/08/10
Description
[CVE-2021-33690] Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure (Component Build Service)
Affected system
type
SAP Business One
Patchday
2021-08
Released
on
2021/08/10
Description
[CVE-2021-33704] Missing Authorization Check in SAP Business One (Service Layer)
Affected system
type
ABAP
Patchday
2021-08
Released
on
2021/08/10
Description
[CVE-2021-33701] SQL Injection vulnerability in SAP NZDT Row Count Reconciliation
Affected system
type
ABAP
Patchday
2021-08
Released
on
2021/06/08
Description
[CVE-2021-21473] Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2021-08
Released
on
2021/08/10
Description
Switchable Authorization checks for RFC in CRM Middleware
Affected system
type
Java
Patchday
2021-08
Released
on
2021/08/10
Description
[CVE-2021-33691] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Development Infrastructure (Notification Service)
Affected system
type
Java
Patchday
2021-07
Released
on
2021/07/13
Description
[CVE-2021-33689] Insufficient Logging in SAP NetWeaver AS for JAVA (Administrator)
Affected system
type
ABAP
Patchday
2021-07
Released
on
2021/07/13
Description
[CVE-2021-33676] Missing authorization check in SAP CRM ABAP
Affected system
type
SAP 3D Visual Enterprise
Patchday
2021-07
Released
on
2021/07/13
Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
Kernel
Patchday
2021-07
Released
on
2021/07/13
Description
[CVE-2021-33684] Memory Corruption in SAP NetWeaver AS ABAP and ABAP Platform
Affected system
type
Kernel
Patchday
2021-07
Released
on
2021/07/13
Description
[CVE-2021-33683] HTTP Request Smuggling in SAP Web Dispatcher and Internet Communication Manager
Affected system
type
ABAP
Patchday
2021-07
Released
on
2021/07/13
Description
[CVE-2021-33678] Code Injection vulnerability in SAP NetWeaver AS ABAP (Reconciliation Framework)
Affected system
type
Java
Patchday
2021-07
Released
on
2021/07/13
Description
[CVE-2021-33687] Information Disclosure in SAP NetWeaver AS for Java (Enterprise Portal)
Affected system
type
BI/BO platform
Patchday
2021-07
Released
on
2021/07/13
Description
[CVE-2021-33667] Information Disclosure in SAP Business Objects Web Intelligence (BI Launchpad)
Affected system
type
Java
Patchday
2021-07
Released
on
2021/07/13
Description
[CVE-2021-33671] Missing Authorization check in SAP NetWeaver Guided Procedures
Affected system
type
ABAP
Patchday
2021-07
Released
on
2021/07/13
Description
[CVE-2021-33677] Information Disclosure in SAP NetWeaver AS ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2021-07
Released
on
2021/06/08
Description
[CVE-2021-27610] Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform
Affected system
type
Java
Patchday
2021-07
Released
on
2021/07/13
Description
[CVE-2021-33670] Denial of Service (DoS) in SAP NetWeaver AS for Java (Http Service)
Affected system
type
SAP Lumira Server
Patchday
2021-07
Released
on
2021/07/13
Description
[CVE-2021-33682] Cross-Site Scripting (XSS) vulnerability in SAP Lumira Server
Affected system
type
ABAP
Patchday
2021-06
Released
on
2021/06/08
Description
[CVE-2021-33664] Cross-Site Scripting (XSS) vulnerability within SAP NetWeaver AS ABAP (Applications based on Web Dynpro ABAP)
Affected system
type
ABAP
Patchday
2021-06
Released
on
2021/06/08
Description
[CVE-2021-33663] Plaintext Injection in SAP NetWeaver AS for ABAP
Affected system
type
ABAP
Patchday
2021-06
Released
on
2021/05/25
Description
Incomplete authorization checks for import of environmental data
Affected system
type
ABAP
Patchday
2021-06
Released
on
2021/06/08
Description
[CVE-2021-33665] Cross-Site Scripting (XSS) vulnerability within SAP NetWeaver AS ABAP (Applications based on SAP GUI for HTML)
Affected system
type
Java
Patchday
2021-06
Released
on
2021/06/08
Description
[CVE-2021-27635] Missing XML Validation in SAP NetWeaver AS for JAVA
Affected system
type
SAP Enable Now
Patchday
2021-06
Released
on
2021/06/08
Description
[CVE-2021-27637] Information Disclosure in SAP Enable Now (SAP Workforce Performance Builder - Manager)
Affected system
type
Internet Graphics Service
Patchday
2021-06
Released
on
2021/06/08
Description
[Multiple CVEs] Memory Corruption vulnerability in SAP Internet Graphics Service
Affected system
type
SAP Commerce Cloud
Patchday
2021-06
Released
on
2021/06/08
Description
[CVE-2021-33666] Cross-Site Scripting (XSS) in SAP Commerce Cloud
Affected system
type
Java
Patchday
2021-06
Released
on
2021/06/08
Description
[CVE-2021-27615] Cross-Site Scripting (XSS) vulnerability in SAP Manufacturing Execution
Affected system
type
SAP GUI / Frontend
Patchday
2021-05
Released
on
2021/05/11
Description
[CVE-2021-27612] SAP GUI for Windows is vulnerable to redirect users to an untrusted website
Affected system
type
SAP Business One
Patchday
2021-05
Released
on
2021/05/11
Description
[CVE-2021-27616] Multiple vulnerabilities in SAP Business One, version for SAP HANA (Business-One-Hana-Chef-Cookbook)
Affected system
type
ABAP
Patchday
2021-05
Released
on
2021/05/11
Description
[CVE-2021-27611] Code Injection vulnerability in SAP NetWeaver AS ABAP
Affected system
type
SAP Business One
Patchday
2021-05
Released
on
2021/05/11
Description
[CVE-2021-27613] Information Disclosure in SAP Business One (Chef business-one-cookbook)
Affected system
type
SAP Commerce Cloud
Patchday
2021-05
Released
on
2021/05/11
Description
[CVE-2021-27619] Information Disclosure in SAP Commerce (Backoffice search)
Affected system
type
Java
Patchday
2021-05
Released
on
2021/05/11
Description
Information Disclosure in Enterprise Services Repository of SAP Process Integration
Affected system
type
Java
Patchday
2021-05
Released
on
2021/05/11
Description
[Multiple CVEs] Multiple vulnerabilities in SAP Process Integration (Integration Builder Framework)
Affected system
type
SAP CRM UI
Patchday
2021-05
Released
on
2021/04/27
Description
Cross-Site Request Forgery (CSRF) vulnerability in SAP CRM WebClient UI
Affected system
type
ABAP
Patchday
2021-05
Released
on
2021/04/27
Description
Unauthorized use of application functions in SAP GUI for HTML
Affected system
type
BI/BO platform
Patchday
2021-04
Released
on
2021/04/13
Description
Information Disclosure in BOE/CMC application
Affected system
type
SAP Solution Manager...
Patchday
2021-04
Released
on
2021/04/13
Description
[CVE-2021-27609] Missing Authorization check in SAP Focused RUN
Affected system
type
Java
Patchday
2021-04
Released
on
2021/04/13
Description
[CVE-2021-27601] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java (Applications based on HTMLB for Java)
Affected system
type
Java
Patchday
2021-04
Released
on
2021/04/13
Description
[CVE-2021-21482] Information Disclosure in SAP NetWeaver Master Data Management
Affected system
type
ABAP
Patchday
2021-04
Released
on
2021/04/13
Description
[CVE-2021-27603] Denial of Service (DoS) in SAP NetWeaver AS of ABAP
Affected system
type
Java
Patchday
2021-04
Released
on
2021/04/13
Description
[CVE-2021-27604] Potential XXE Vulnerability in SAP Process Integration (ESR Java Mappings)
Affected system
type
SAP Solution Manager
Patchday
2021-04
Released
on
2021/04/13
Description
[CVE-2021-21483] Information Disclosure in SAP Solution Manager
Affected system
type
Java
Patchday
2021-04
Released
on
2021/04/13
Description
[CVE-2021-21492] Content spoofing in NetWeaver AS Java HTTP Service
Affected system
type
Java
Patchday
2021-04
Released
on
2021/04/13
Description
[CVE-2021-27599] Information Disclosure in SAP Process Integration (Integration Builder Framework)
Affected system
type
ABAP
Patchday
2021-04
Released
on
2021/04/13
Description
Update 1 to Security Note 1576763: Potential information disclosure relating to usernames
Affected system
type
Java
Patchday
2021-04
Released
on
2021/04/13
Description
[CVE-2021-27598] Improper Access Control in SAP NetWeaver AS for Java (Customer Usage Provisioning Servlet)
Affected system
type
ABAP
Patchday
2021-04
Released
on
2021/04/13
Description
[CVE-2021-27605 ] Missing Authorization check in HCM Travel Management Fiori Apps V2
Affected system
type
SAP 3D Visual Enterprise
Patchday
2021-04
Released
on
2021/03/18
Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
Java
Patchday
2021-04
Released
on
2021/04/13
Description
Clickjacking vulnerability in Runtime Workbench of SAP Process Integration
Affected system
type
Java
Patchday
2021-04
Released
on
2021/04/13
Description
[CVE-2021-27600 ] Cross-Site Scripting (XSS) vulnerability in SAP Manufacturing Execution (System Rules)
Affected system
type
Java
Patchday
2021-04
Released
on
2021/04/13
Description
[CVE-2021-21485] Information Disclosure in SAP NetWeaver AS for Java (Telnet Commands)
Affected system
type
SAP GUI / Frontend
Patchday
2021-04
Released
on
2021/04/13
Description
[CVE-2021-27608] Unquoted Search Path in SAPSetup
Affected system
type
SAP Commerce / SAP...
Patchday
2021-04
Released
on
2021/04/13
Description
[CVE-2021-27602] Remote Code Execution vulnerability in Source Rules of SAP Commerce
Affected system
type
ABAP
Patchday
2021-04
Released
on
2021/03/23
Description
Cross-Site Request Forgery (CSRF) vulnerability in S/4HANA Finance for advanced payment management
Affected system
type
SAP 3D Visual Enterprise
Patchday
2021-03
Released
on
2021/03/09
Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
SAP HANA Platform
Patchday
2021-03
Released
on
2021/03/09
Description
[CVE-2021-21484] Possible authentication bypass in SAP HANA LDAP scenarios
Affected system
type
Java
Patchday
2021-03
Released
on
2021/03/09
Description
[CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence
Affected system
type
Java
Patchday
2021-03
Released
on
2021/03/09
Description
Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on HTMLB for Java)
Affected system
type
SAP 3D Visual Enterprise
Patchday
2021-03
Released
on
2021/03/09
Description
[CVE-2021-27592] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
Java
Patchday
2021-03
Released
on
2021/03/09
Description
[CVE-2021-21491] Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on Web Dynpro Java)
Affected system
type
Java
Patchday
2021-03
Released
on
2021/03/09
Description
[CVE-2021-21488] Insecure deserialisation in SAP NetWeaver Knowledge Management
Affected system
type
ABAP
Patchday
2021-03
Released
on
2021/02/23
Description
Switchable Authorization checks for RFC in In House Cash
Affected system
type
Java
Patchday
2021-03
Released
on
2021/03/09
Description
[CVE-2021-21481] Missing Authorization Check in SAP NetWeaver AS JAVA (MigrationService)
Affected system
type
Java
Patchday
2021-03
Released
on
2021/03/09
Description
Reverse tabnabbing issue in Unified Rendering based frameworks in NetWeaver Application Server Java
Affected system
type
ABAP
Patchday
2021-03
Released
on
2021/03/09
Description
[CVE-2021-21486] Missing Authorization check in SAP Enterprise Financial Services( Bank Customer Accounts )
Affected system
type
ABAP
Patchday
2021-03
Released
on
2021/03/09
Description
[CVE-2021-21487] Missing Authorization Check in Payment Engine
Affected system
type
ABAP
Patchday
2021-02
Released
on
2021/02/09
Description
[CVE-2021-21478] Reverse Tabnabbing vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP)
Affected system
type
ABAP
Patchday
2021-02
Released
on
2021/02/09
Description
Missing Authorization Checks in the Monitor Data and My Data Collections Apps
Affected system
type
Java
Patchday
2021-02
Released
on
2021/02/09
Description
[CVE-2021-21475] Directory Traversal vulnerability in SAP NetWeaver Master Data Management 7.1
Affected system
type
ABAP
Patchday
2021-02
Released
on
2021/02/09
Description
Reverse Tabnabbing vulnerability within SAP CRM WebClient UI
Affected system
type
Java
Patchday
2021-02
Released
on
2021/02/09
Description
Clickjacking vulnerability in Cloud Integration Content of SAP Process Integration
Affected system
type
SAP Commerce Cloud
Patchday
2021-02
Released
on
2021/02/09
Description
[CVE-2021-21477] Remote Code Execution vulnerability in SAP Commerce
Affected system
type
Java
Patchday
2021-02
Released
on
2021/02/09
Description
Clickjacking vulnerability in Adapter Runtime of SAP Process Integration
Affected system
type
BI/BO platform
Patchday
2021-02
Released
on
2021/02/09
Description
[CVE-2021-21444] Clickjacking vulnerability in SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad)
Affected system
type
SAP Netweaver
Patchday
2021-02
Released
on
2021/02/09
Description
[CVE-2021-21472] Server password not set during installation of SAP NetWeaver Master Data Management 7.1
Affected system
type
SAP HANA Platform
Patchday
2021-02
Released
on
2021/02/09
Description
[CVE-2021-21474] SAML Assertion Signature MD5 Digest Algorithm Vulnerability in SAP HANA Database
Affected system
type
Kernel
Patchday
2021-02
Released
on
2021/02/09
Description
Reverse Tabnabbing vulnerability within SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML)
Affected system
type
ABAP
Patchday
2021-01
Released
on
2021/01/12
Description
Cross-Site Request Forgery (CSRF) vulnerability in Cash Management
Affected system
type
ABAP
Patchday
2021-01
Released
on
2021/01/12
Description
Switchable authorization checks for RFC module in In-House-Cash.
Affected system
type
ABAP
Patchday
2021-01
Released
on
2021/01/12
Description
[CVE-2021-21465] Multiple vulnerabilities in SAP Business Warehouse (Database Interface)
Affected system
type
Analysis for Office
Patchday
2021-01
Released
on
2021/01/12
Description
[CVE-2021-21470] XML External Entity vulnerability in SAP EPM add-in
Affected system
type
ABAP
Patchday
2021-01
Released
on
2021/01/12
Description
[CVE-2021-21467] Missing Authorization check in SAP Banking Services (Generic Market Data)
Affected system
type
SAP 3D Visual Enterprise
Patchday
2021-01
Released
on
2021/01/12
Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
Java
Patchday
2021-01
Released
on
2021/01/12
Description
[CVE-2021-21469] Information Disclosure in SAP NetWeaver Master Data Management
Affected system
type
ABAP
Patchday
2021-01
Released
on
2021/01/12
Description
[CVE-2021-21446] Denial of service (DOS) in SAP NetWeaver AS ABAP and ABAP Platform
Affected system
type
SAP GUI / Frontend
Patchday
2021-01
Released
on
2021/01/12
Description
[CVE-2021-21448] Information Disclosure in SAP GUI for Windows
Affected system
type
SAP Commerce Cloud
Patchday
2021-01
Released
on
2021/01/12
Description
[CVE-2021-21445] Header Manipulation vulnerability in SAP Commerce Cloud
Affected system
type
BI/BO platform
Patchday
2021-01
Released
on
2021/01/12
Description
[CVE-2021-21447] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)
Affected system
type
ABAP
Patchday
2021-01
Released
on
2021/01/12
Description
[CVE-2021-21466] Code Injection in SAP Business Warehouse and SAP BW/4HANA
Affected system
type
Cloud Foundry
Patchday
2021-01
Released
on
2020/12/22
Description
Information Disclosure in Central Order