We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.
We hope you enjoy using it!
We have found 14 security advices for you to review.
Severity
SAP© Security advisories 14
System Types
Affected SAP© system types
Affected system
type
SAP Adaptive Server...
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-31594] Privilege escalation vulnerability in SAP Adaptive Server Enterprise (ASE)
Affected system
type
ABAP
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-31589] Segregation of Duty vulnerability in IL FI-AP File from SHAAM program.
Affected system
type
SAP 3D Visual Enterprise
Patchday
2022-06
Released
on
2022/06/14
Description
[Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
Affected system
type
Java
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-29615] Multiple vulnerabilities associated with Apache log4j 1.x component in SAP NetWeaver Developer Studio (NWDS)
Affected system
type
SAP...
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-29618] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Development Infrastructure (Design Time Repository)
Affected system
type
SAP Financial Consolidation
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-31595] Privilege escalation vulnerability in SAP Financial Consolidation
Affected system
type
ABAP SAP Host Agent
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-29612] Server-Side Request Forgery in SAP NetWeaver, ABAP Platform and SAP Host Agent
Affected system
type
UI5
Patchday
2022-06
Released
on
2022/06/14
Description
Unsafe use of target blank in SAP Marketing Campaigns
Affected system
type
ABAP Java HANA platform
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-29614] Privilege Escalation in SAP startservice of SAP NetWeaver AS ABAP, AS Java, ABAP Platform and HANA Database
Affected system
type
UI5
Patchday
2022-06
Released
on
2022/06/14
Description
Cross-Site Scripting (XSS) vulnerability in SAP Marketing Campaigns App
Affected system
type
SAP PowerDesigner
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-31590] Potential privilege escalation in SAP PowerDesigner Proxy 16.7
Affected system
type
Java
Patchday
2022-06
Released
on
2022/06/14
Description
Improper Access Control check in SAP NetWeaver basicadmin and adminadapter services
Affected system
type
ABAP
Patchday
2022-06
Released
on
2022/06/14
Description
Missing Authorization check in SAP ERP HCM
Affected system
type
SAProuter
Patchday
2022-06
Released
on
2022/06/14
Description
[CVE-2022-27668] Improper Access Control of SAProuter for SAP NetWeaver and ABAP Platform