We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.
We hope you enjoy using it!
This time we found critical correction advisiories. We count 28 and the highest CVSS score is 9.8.
Severity
SAP© Security advisories 28
System Types
Affected SAP© system types
Affected system
type
BI/BO platform
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-27671] CSRF token visible in one of the URL in SAP Business Intelligence Platform.
Affected system
type
Java
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-28217] Missing XML Validation vulnerability in SAP NW EP WPC
Affected system
type
BI/BO platform
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-28213] Missing XML Validation vulnerability in SAP BusinessObjects Business Intelligence Platform (dswsbobje - SOAP Web services)
Affected system
type
BI/BO platform
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-22541] Information Disclosure vulnerability in SAP BusinessObjects Platform
Affected system
type
Java
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-26105] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
Sybase
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-27670] Denial of service (DOS) in SQL Anywhere
Affected system
type
SAP HANA Platform
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP HANA Extended Application Services
Affected system
type
BI/BO platform
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-28216] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI Workspace)
Affected system
type
Adobe LiveCycle Designer
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2021-44832] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP NetWeaver ABAP Server and ABAP Platform (Adobe LiveCycle Designer 11.0)
Affected system
type
Kernel
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-28772]Denial of service (DOS) in SAP Web Dispatcher and SAP Netweaver (Internet Communication Manager)
Affected system
type
BI/BO platform
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-27667] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (CMC)
Affected system
type
SAP GUI / Frontend
Patchday
2022-04
Released
on
2022/04/12
Description
Information Disclosure vulnerability in SAP GUI for Windows
Affected system
type
SAP Customer...
Patchday
2022-04
Released
on
2022/04/14
Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Profitability Analytics
Affected system
type
ABAP
Patchday
2022-04
Released
on
2022/04/12
Description
Multiple Vulnerabilities in URI.js bundled with SAPUI5
Affected system
type
ABAP
Patchday
2022-04
Released
on
2022/04/12
Description
Prepare CSP support for On-Premise down port for code dependency in SAP CRM WebClient UI
Affected system
type
ABAP
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-28770] Cross-Site Scripting (XSS) vulnerability in SAPUI5 (vbm library)
Affected system
type
SAP Customer Checkout
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Checkout
Affected system
type
SAP 3D Visual Enterprise
Patchday
2022-04
Released
on
2022/04/12
Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
Java
Patchday
2022-04
Released
on
2022/04/12
Description
Update 1 to Security Note 3022622 - [CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence
Affected system
type
SAP Innovation Management
Patchday
2022-04
Released
on
2022/03/28
Description
[CVE-2022-27658] Missing authorization check in SAP Innovation Management
Affected system
type
SAP Commerce
Patchday
2022-04
Released
on
2022/04/12
Description
Privilege escalation vulnerability in Apache Tomcat server component of SAP Commerce
Affected system
type
Java
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-27669] Missing Authentication check in XML Data Archiving Service
Affected system
type
SAP Solution Manager...
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-27657] Directory Traversal vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)
Affected system
type
ABAP
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-28215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform
Affected system
type
Any
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-22965] Central Security Note for Remote Code Execution vulnerability associated with Spring Framework
Affected system
type
Java
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in PowerDesigner Web (up to including 16.7 SP05 PL01)
Affected system
type
SAP Commerce
Patchday
2022-04
Released
on
2022/04/18
Description
[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Commerce
Affected system
type
Kernel
Patchday
2022-04
Released
on
2022/04/12
Description
[CVE-2022-28773] Denial of service (DOS) in SAP Web Dispatcher and SAP Netweaver (Internet Communication Manager)