We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.
We hope you enjoy using it!
This time we found critical correction advisiories. We count 13 and the highest CVSS score is 9.9.
Severity
SAP© Security advisories 13
System Types
Affected SAP© system types
Affected system
type
Java
Patchday
2023-09
Released
on
2023/09/12
Description
Denial of service (DOS) vulnerability due to the usage of vulnerable version of Commons File Upload in SAP Quotation Management Insurance (FS-QUO)
Affected system
type
BI/BO platform
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-37489] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Version Management System)
Affected system
type
ABAP
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-40625] Missing Authorization check in Manage Purchase Contracts App
Affected system
type
ABAP
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-40624] Code Injection vulnerability in SAP NetWeaver AS ABAP (applications based on Unified Rendering)
Affected system
type
BI/BO platform
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-42472] Insufficient File type validation in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)
Affected system
type
Java
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-41367] Missing Authentication check in SAP NetWeaver (Guided Procedures)
Affected system
type
ABAP
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-41369] External Entity Loop vulnerability in SAP S/4HANA (Create Single Payment application)
Affected system
type
Kernel, HANA...
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-40309] Missing Authorization check in SAP CommonCryptoLib
Affected system
type
Kernel
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-40308] Memory Corruption vulnerability in SAP CommonCryptoLib
Affected system
type
BI/BO platform
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-40623] Arbitrary File Delete via Directory Junction in SAP BusinessObjects Suite(installer)
Affected system
type
PowerDesigner
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-40621] Code Injection vulnerability in SAP PowerDesigner Client
Affected system
type
ABAP
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-41368] Insecure Direct Object Reference (IDOR) vulnerability in SAP S/4HANA (Manage checkbook apps)
Affected system
type
SAP BI
Patchday
2023-09
Released
on
2023/09/12
Description
[CVE-2023-40622] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management)