We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.
We hope you enjoy using it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 120 and the highest CVSS score is 9.8.

 

 Severity
SAP© Security advisories 120
 System Types
Affected SAP© system types

 

Related note
3479293
CVSS
4.3

Affected system type
ABAP
Patchday
2024-10
Released on
2024/08/13

Description
[CVE-2024-42373] Missing Authorization Check in SAP Student Life Cycle Management (SLcM)

 

Related note
3477359
CVSS
6.0

Affected system type
Java
Patchday
2024-10
Released on
2024/09/10

Description
[CVE-2024-45283] Information disclosure vulnerability in SAP NetWeaver AS for Java (Destination Service)

 

Related note
3503462
CVSS
5.4

Affected system type
Java
Patchday
2024-10
Released on
2024/10/08

Description
[CVE-2024-47594] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC)

 

Related note
3481588
CVSS
4.3

Affected system type
ABAP
Patchday
2024-10
Released on
2024/09/10

Description
[CVE-2024-41729] Information Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer)

 

Related note
3523541
CVSS
8.0

Affected system type
SAP Enterprise...
Patchday
2024-10
Released on
2024/10/08

Description
[CVE-2022-23302] Multiple vulnerabilities in SAP Enterprise Project Connection

 

Related note
3507545
CVSS
5.4

Affected system type
SAP Commerce / SAP...
Patchday
2024-10
Released on
2024/10/08

Description
[CVE-2024-45278] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice

 

Related note
3495876
CVSS
6.5

Affected system type
Sybase platform
Patchday
2024-10
Released on
2024/08/13

Description
[Multiple CVEs] Multiple vulnerabilities in SAP Replication Server (FOSS)

 

Related note
3520100
CVSS
4.3

Affected system type
SAP HANA Client
Patchday
2024-10
Released on
2024/10/08

Description
[CVE-2024-45277] Prototype Pollution vulnerability in SAP HANA Client

 

Related note
3479478
CVSS
9.8

Affected system type
BI/BO platform
Patchday
2024-10
Released on
2024/08/13

Description
[CVE-2024-41730] Missing Authentication check in SAP BusinessObjects Business Intelligence Platform

 

Related note
3478615
CVSS
7.7

Affected system type
BI/BO platform
Patchday
2024-10
Released on
2024/10/08

Description
[CVE-2024-37179] Insecure File Operations vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)

 

Related note
3454858
CVSS
4.1

Affected system type
ABAP
Patchday
2024-10
Released on
2024/07/09

Description
[CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
3251893
CVSS
4.3

Affected system type
ABAP
Patchday
2024-10
Released on
2024/09/24

Description
[CVE-2024-45282] HTTP Verb Tampering in SAP S/4 HANA(Manage Bank Statements)

 

Related note
3525971
CVSS
4.3

Affected system type
ABAP
Patchday
2024-10
Released on
2024/10/10

Description
Other vulnerability in service UI_PRODUCTIONVERSION

 

Related note
3459935
CVSS
7.4

Affected system type
SAP Commerce Cloud
Patchday
2024-09
Released on
2024/08/13

Description
[CVE-2024-33003] Information Disclosure Vulnerability in SAP Commerce Cloud

 

Related note
3437585
CVSS
4.3

Affected system type
ABAP
Patchday
2024-09
Released on
2024/08/27

Description
[CVE-2024-44121] Information Disclosure in SAP S/4 HANA (Statutory Reports)

 

Related note
3496410
CVSS
2.7

Affected system type
ABAP
Patchday
2024-09
Released on
2024/09/10

Description
[CVE-2024-41728] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
3481992
CVSS
4.3

Affected system type
ABAP
Patchday
2024-09
Released on
2024/09/10

Description
[CVE-2024-44113] Information Disclosure vulnerability in the SAP Business Warehouse (BEx Analyzer)

 

Related note
2256627
CVSS
2.7

Affected system type
ABAP
Patchday
2024-09
Released on
2024/09/10

Description
[CVE-2024-45284] Missing authorization check in SAP Student Life Cycle Management (SLcM)

 

Related note
3498221
CVSS
4.7

Affected system type
Java
Patchday
2024-09
Released on
2024/09/10

Description
[CVE-2024-44120] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

 

Related note
3501359
CVSS
6.1

Affected system type
ABAP
Patchday
2024-09
Released on
2024/09/10

Description
[CVE-2024-45279] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP(CRM Blueprint Application Builder Panel)

 

Related note
3505293
CVSS
4.3

Affected system type
ABAP
Patchday
2024-09
Released on
2024/09/10

Description
[CVE-2024-44112] Missing Authorization check in SAP for Oil & Gas (Transportation and Distribution)

 

Related note
3507252
CVSS
2.0

Affected system type
ABAP
Patchday
2024-09
Released on
2024/09/10

Description
[CVE-2024-44114] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
3430336
CVSS
5.9

Affected system type
SAP Commerce Cloud
Patchday
2024-09
Released on
2024/09/10

Description
[CVE-2013-3587] Information Disclosure vulnerability in SAP Commerce Cloud

 

Related note
3505503
CVSS
4.8

Affected system type
Java
Patchday
2024-09
Released on
2024/09/10

Description
[CVE-2024-45280] Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver AS Java (Logon Application)

 

Related note
3488039
CVSS
5.4

Affected system type
ABAP
Patchday
2024-09
Released on
2024/09/10

Description
[Multiple CVEs] Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
3497347
CVSS
6.1

Affected system type
ABAP
Patchday
2024-09
Released on
2024/09/10

Description
[CVE-2024-42378] Cross-Site Scripting (XSS) in eProcurement on S/4HANA

 

Related note
3488341
CVSS
6.5

Affected system type
ABAP
Patchday
2024-09
Released on
2024/09/10

Description
[CVE-2024-45286] Missing Authorization check in SAP Production and Revenue Accounting (Tobin interface)

 

Related note
3425287
CVSS
5.8

Affected system type
BI/BO platform
Patchday
2024-09
Released on
2024/09/10

Description
[CVE-2024-45281] DLL hijacking vulnerability in SAP BusinessObjects Business Intelligence Platform

 

Related note
3471450
CVSS
5.3

Affected system type
SAP Commerce
Patchday
2024-08
Released on
2024/08/13

Description
[CVE-2024-41733] Information Disclosure Vulnerability in SAP Commerce

 

Related note
3433545
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2024-08
Released on
2024/08/13

Description
[CVE-2024-42375] Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform

 

Related note
3485284
CVSS
8.2

Affected system type
Java
Patchday
2024-08
Released on
2024/08/13

Description
[CVE-2024-42374] XML injection in SAP BEx Web Java Runtime Export Web Service

 

Related note
3474590
CVSS
6.5

Affected system type
ABAP
Patchday
2024-08
Released on
2024/08/13

Description
[CVE-2024-42376] Multiple Missing Authorization Check vulnerabilities in SAP Shared Service Framework

 

Related note
3423268
CVSS
7.8

Affected system type
SAP Fiori
Patchday
2024-08
Released on
2024/07/23

Description
[CVE-2023-30533] Prototype Pollution in SAP S/4 HANA (Manage Supply Protection)

 

Related note
3483256
CVSS
5.4

Affected system type
SAP Commerce
Patchday
2024-08
Released on
2024/08/13

Description
[CVE-2024-41735] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice

 

Related note
3468102
CVSS
4.7

Affected system type
ABAP
Patchday
2024-08
Released on
2024/08/13

Description
[CVE-2024-41732] Improper Access Control in SAP Netweaver Application Server ABAP

 

Related note
3477423
CVSS
4.3

Affected system type
ABAP
Patchday
2024-08
Released on
2024/08/13

Description
[CVE-2024-39591] Missing Authorization check in SAP Document Builder

 

Related note
3438085
CVSS
6.3

Affected system type
Kernel / Web Dispatcher
Patchday
2024-08
Released on
2024/08/13

Description
[CVE-2024-33005] Missing Authorization check in SAP NetWeaver Application Server (ABAP and Java),SAP Web Dispatcher and SAP Content Server.

 

Related note
3477196
CVSS
9.1

Affected system type
SAP Build Apps
Patchday
2024-08
Released on
2024/08/13

Description
[CVE-2024-29415] Server-Side Request Forgery vulnerability in applications built with SAP Build Apps

 

Related note
3475427
CVSS
4.3

Affected system type
SAP Fiori
Patchday
2024-08
Released on
2024/08/13

Description
[CVE-2024-41736] Information Disclosure vulnerability in SAP Permit to Work

 

Related note
3494349
CVSS
4.3

Affected system type
ABAP
Patchday
2024-08
Released on
2024/08/13

Description
[CVE-2024-41734] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform

 

Related note
3487537
CVSS
5.0

Affected system type
ABAP
Patchday
2024-08
Released on
2024/08/13

Description
[CVE-2024-41737] Server-Side Request Forgery (SSRF) in SAP CRM ABAP (Insights Management)

 

Related note
3476340
CVSS
3.3

Affected system type
SAP Enable Now
Patchday
2024-07
Released on
2024/07/09

Description
[CVE-2024-34692] Unrestricted File upload vulnerability in SAP Enable Now

 

Related note
3467377
CVSS
6.1

Affected system type
SAP CRM UI
Patchday
2024-07
Released on
2024/07/09

Description
[Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI)

 

Related note
3485805
CVSS
5.0

Affected system type
ABAP
Patchday
2024-07
Released on
2024/07/09

Description
[CVE-2024-34689] Allowlisting of callback-URLs in SAP Business Workflow (WebFlow Services)

 

Related note
3490515
CVSS
7.2

Affected system type
SAP Commerce
Patchday
2024-07
Released on
2024/07/09

Description
[CVE-2024-39597] Improper Authorization Checks on Early Login Composable Storefront B2B sites of SAP Commerce

 

Related note
3457354
CVSS
5.4

Affected system type
ABAP
Patchday
2024-07
Released on
2024/07/09

Description
[CVE-2024-37172] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)

 

Related note
3469958
CVSS
5.0

Affected system type
ABAP
Patchday
2024-07
Released on
2024/07/09

Description
[CVE-2024-37171] Server-Side Request Forgery (SSRF) in SAP Transportation Management (Collaboration Portal)

 

Related note
3456952
CVSS
4.7

Affected system type
ABAP
Patchday
2024-07
Released on
2024/07/09

Description
[CVE-2024-39599] Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform

 

Related note
3476348
CVSS
4.3

Affected system type
SAP Enable Now
Patchday
2024-07
Released on
2024/07/09

Description
[CVE-2024-39596] Missing Authorization check vulnerability in SAP Enable Now

 

Related note
3466801
CVSS
6.9

Affected system type
SAP Landscape...
Patchday
2024-07
Released on
2024/07/09

Description
[CVE-2024-39593] Information Disclosure vulnerability in SAP Landscape Management

 

Related note
3482217
CVSS
6.1

Affected system type
ABAP
Patchday
2024-07
Released on
2024/07/09

Description
[CVE-2024-39594] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Business Warehouse - Business Planning and Simulation

 

Related note
3461110
CVSS
5.0

Affected system type
SAP GUI
Patchday
2024-07
Released on
2024/07/09

Description
[CVE-2024-39600] Information Disclosure vulnerability in SAP GUI for Windows

 

Related note
3483993
CVSS
5.0

Affected system type
ABAP
Patchday
2024-07
Released on
2024/07/09

Description
[CVE-2024-34689] Prerequisite for Security Note 3458789

 

Related note
3468681
CVSS
6.1

Affected system type
Java
Patchday
2024-07
Released on
2024/07/09

Description
[CVE-2024-34685] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Knowledge Management XMLEditor

 

Related note
3458789
CVSS
5.0

Affected system type
ABAP
Patchday
2024-07
Released on
2024/07/09

Description
[CVE-2024-34689] Server-Side Request Forgery in SAP Business Workflow (WebFlow Services)

 

Related note
3460407
CVSS
7.5

Affected system type
Java
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-34688] Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)

 

Related note
3457265
CVSS
5.4

Affected system type
ABAP
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-34690] Missing Authorization check in SAP Student Life Cycle Management (SLcM)

 

Related note
3453170
CVSS
6.5

Affected system type
ABAP
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-33001] Denial of service (DOS) in SAP NetWeaver and ABAP platform

 

Related note
3459379
CVSS
6.5

Affected system type
ABAP
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-34683] Unrestricted file upload in SAP Document Builder (HTTP service)

 

Related note
3465455
CVSS
5.5

Affected system type
ABAP
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-37176] Missing Authorization check in SAP BW/4HANA Transformation and DTP

 

Related note
3441817
CVSS
3.7

Affected system type
BI/BO platform
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-34684] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Scheduling)

 

Related note
3425571
CVSS
5.3

Affected system type
Java
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-28164] Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures)

 

Related note
3465129
CVSS
6.1

Affected system type
ABAP
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-34686] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)

 

Related note
3466175
CVSS
6.5

Affected system type
ABAP
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-34691] Missing Authorization check in SAP S/4HANA (Manage Incoming Payment Files)

 

Related note
3457592
CVSS
8.1

Affected system type
SAP Financial Consolidation
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-37177] Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation

 

Related note
1938764
CVSS
4.2

Affected system type
ABAP
Patchday
2024-05
Released on
2024/05/14

Description
[CVE-2024-33009] SQL injection vulnerability in SAP Global Label Management (GLM)

 

Related note
3450286
CVSS
6.1

Affected system type
ABAP
Patchday
2024-05
Released on
2024/05/14

Description
[CVE-2024-32733] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform

 

Related note
3434666
CVSS
4.3

Affected system type
ABAP
Patchday
2024-05
Released on
2024/05/14

Description
[Multiple CVEs] Missing Authorization Checks in SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)

 

Related note
3449093
CVSS
4.3

Affected system type
BI/BO platform
Patchday
2024-05
Released on
2024/05/14

Description
[CVE-2024-33004] Insecure Storage vulnerability in SAP BusinessObjects Business Intelligence Platform (Webservices)

 

Related note
3448445
CVSS
6.5

Affected system type
ABAP
Patchday
2024-05
Released on
2024/05/14

Description
[CVE-2024-34687] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application server for ABAP and ABAP Platform

 

Related note
3431794
CVSS
8.1

Affected system type
BI/BO platform
Patchday
2024-05
Released on
2024/05/14

Description
[CVE-2024-28165] Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform

 

Related note
3460772
CVSS
6.1

Affected system type
ABAP
Patchday
2024-05
Released on
2024/05/14

Description
[CVE-2024-33002] Cross-Site Scripting (XSS) Vulnerability in SAP S/4HANA (Document Service Handler for DPS)

 

Related note
3448171
CVSS
9.6

Affected system type
ABAP
Patchday
2024-05
Released on
2024/05/14

Description
[CVE-2024-33006] File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform

 

Related note
3349468
CVSS
4.9

Affected system type
Sybase platform
Patchday
2024-05
Released on
2024/05/14

Description
[CVE-2024-33008] Memory Corruption vulnerability in SAP Replication Server

 

Related note
3446076
CVSS
3.5

Affected system type
ABAP
Patchday
2024-05
Released on
2024/05/14

Description
[CVE-2024-33007] Client-side script execution vulnerability in SAP UI5(PDFViewer)

 

Related note
3447467
CVSS
5.5

Affected system type
ABAP
Patchday
2024-05
Released on
2024/05/14

Description
[CVE-2024-32731] Missing Authorization check in SAP My Travel Requests

 

Related note
3455438
CVSS
9.8

Affected system type
SAP Commerce Cloud
Patchday
2024-05
Released on
2024/05/14

Description
[CVE-2019-17495] Multiple vulnerabilities in SAP CX Commerce

 

Related note
3421384
CVSS
7.7

Affected system type
BI/BO platform
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-25646] Information Disclosure vulnerability in SAP BusinessObjects Web Intelligence

 

Related note
3421453
CVSS
4.8

Affected system type
SAP Business Connector
Patchday
2024-04
Released on
2024/04/09

Description
[Multiple CVEs] Cross-Site Scripting (XSS) vulnerabilities in SAP Business Connector

 

Related note
3430173
CVSS
4.3

Affected system type
ABAP
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-30217] Missing Authorization check in SAP S/4 HANA (Cash Management)

 

Related note
3359778
CVSS
6.5

Affected system type
Kernel
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-30218] Denial of service (DOS) vulnerability in SAP NetWeaver AS ABAP and ABAP Platform

 

Related note
3425188
CVSS
5.3

Affected system type
Java
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-27898] Server-Side Request Forgery in SAP NetWeaver (tc~esi~esp~grmg~wshealthcheck~ear)

 

Related note
3427178
CVSS
4.3

Affected system type
ABAP
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-30216] Missing Authorization check in SAP S/4 HANA (Cash Management)

 

Related note
3434839
CVSS
8.8

Affected system type
Java
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-27899] Security misconfiguration vulnerability in SAP NetWeaver AS Java User Management Engine

 

Related note
3442741
CVSS
6.8

Affected system type
SAP Edge Integration
Patchday
2024-04
Released on
2024/04/09

Description
Stack overflow vulnerability on the component images of SAP Integration Suite (EDGE INTEGRATION CELL)

 

Related note
3442378
CVSS
6.5

Affected system type
ABAP
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-28167] Missing Authorization check in SAP Group Reporting Data Collection (Enter Package Data)

 

Related note
3438234
CVSS
7.2

Affected system type
ABAP
Patchday
2024-04
Released on
2024/04/09

Description
[CVE-2024-27901] Directory Traversal vulnerability in SAP Asset Accounting

 

Related note
3377979
CVSS
5.4

Affected system type
Kernel
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-27902] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP, applications based on SAPGUI for HTML (WebGUI)

 

Related note
3425274
CVSS
9.4

Affected system type
SAP Build Apps
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2019-10744] Code Injection vulnerability in applications built with SAP Build Apps

 

Related note
3425682
CVSS
5.3

Affected system type
Java
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-25644] Information Disclosure vulnerability in SAP NetWeaver (WSRM)

 

Related note
3414195
CVSS
7.2

Affected system type
BI/BO platform
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2023-50164] Path Traversal Vulnerability in SAP BusinessObjects Business Intelligence Platform (Central Management Console)

 

Related note
3410615
CVSS
7.5

Affected system type
HANA platform
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2023-44487 ] Denial of service (DOS) in SAP HANA XS Classic and HANA XS Advanced

 

Related note
3434192
CVSS
5.3

Affected system type
Java
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-28163] Information Disclosure vulnerability in SAP NetWeaver Process Integration (Support Web Pages)

 

Related note
3419022
CVSS
4.3

Affected system type
ABAP
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-27900]Missing Authorization check in SAP ABAP Platform

 

Related note
3417399
CVSS
4.6

Affected system type
ABAP
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-22133] Improper Access Control in SAP Fiori Front End Server

 

Related note
3428847
CVSS
5.3

Affected system type
Java
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-25645] Information Disclosure vulnerability in SAP NetWeaver (Enterprise Portal)

 

Related note
3433192
CVSS
9.1

Affected system type
Java
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-22127] Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)

 

Related note
2637727
CVSS
6.3

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-24739] Missing authorization check in SAP Bank Account Management

 

Related note
3426111
CVSS
8.6

Affected system type
Java
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-24743] XXE vulnerability in SAP NetWeaver AS Java (Guided Procedures)

 

Related note
3420923
CVSS
9.1

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22131] Code Injection vulnerability in SAP ABA (Application Basis)

 

Related note
2897391
CVSS
4.3

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/01

Description
[CVE-2024-24741] Missing Authorization check in SAP Master Data Governance Material

 

Related note
3410875
CVSS
7.6

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22130] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)

 

Related note
3424610
CVSS
7.4

Affected system type
SAP Cloud Connector
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-25642] Improper Certificate Validation in SAP Cloud Connector

 

Related note
3237638
CVSS
4.3

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-25643] Missing authorization check in SAP Fiori app ("My Overtime Requests")

 

Related note
3158455
CVSS
4.1

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-24742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)

 

Related note
3396109
CVSS
4.7

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22128] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Business Client for HTML

 

Related note
3421659
CVSS
7.4

Affected system type
ABAP
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22132] Code Injection vulnerability in SAP IDES Systems

 

Related note
3360827
CVSS
5.3

Affected system type
Kernel
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-24740] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (SAP Kernel)

 

Related note
3417627
CVSS
8.8

Affected system type
Java
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application)

 

Related note
3404025
CVSS
5.4

Affected system type
SAP Enable Now
Patchday
2024-02
Released on
2024/02/13

Description
[CVE-2024-22129] Cross-Site Scripting (XSS) vulnerability in SAP Companion

 

Related note
3389917
CVSS
7.5

Affected system type
Kernel
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2023-44487] Denial of service (DOS) in SAP Web Dispatcher, SAP NetWeaver Application server ABAP, and ABAP Platform

 

Related note
3412456
CVSS
9.1

Affected system type
BTP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA

 

Related note
3190894
CVSS
3.7

Affected system type
SAP Marketing
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21734] URL Redirection vulnerability in SAP Marketing (Contacts App)

 

Related note
3413475
CVSS
9.1

Affected system type
SAP Edge Integration
Patchday
2024-01
Released on
2024/01/09

Description
[Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell

 

Related note
3387737
CVSS
4.1

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21738] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform

 

Related note
3411869
CVSS
8.4

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21737] Code Injection vulnerability in SAP Application Interface Framework (File Adapter)

 

Related note
3407617
CVSS
7.3

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21735] Improper Authorization check in SAP LT Replication Server

 

Related note
3260667
CVSS
6.4

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21736] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)

 

Related note
3392626
CVSS
4.1

Affected system type
Kernel / Web Dispatcher
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-22124] Information Disclosure vulnerability in SAP NetWeaver Internet Communication Manager

 

Related note
3386378
CVSS
7.4

Affected system type
SAP GUI / Frontend
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-22125] Information Disclosure vulnerability in Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge)

 

 
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2024 by SecurityBridge GmbH

v35.0