We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.
We hope you enjoy using it!
This time we found critical correction advisiories. We count 120 and the highest CVSS score is 9.8.
Severity
SAP© Security advisories 120
System Types
Affected SAP© system types
Affected system
type
ABAP
Patchday
2024-10
Released
on
2024/08/13
Description
[CVE-2024-42373] Missing Authorization Check in SAP Student Life Cycle Management (SLcM)
Affected system
type
Java
Patchday
2024-10
Released
on
2024/09/10
Description
[CVE-2024-45283] Information disclosure vulnerability in SAP NetWeaver AS for Java (Destination Service)
Affected system
type
Java
Patchday
2024-10
Released
on
2024/10/08
Description
[CVE-2024-47594] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC)
Affected system
type
ABAP
Patchday
2024-10
Released
on
2024/09/10
Description
[CVE-2024-41729] Information Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer)
Affected system
type
SAP Enterprise...
Patchday
2024-10
Released
on
2024/10/08
Description
[CVE-2022-23302] Multiple vulnerabilities in SAP Enterprise Project Connection
Affected system
type
SAP Commerce / SAP...
Patchday
2024-10
Released
on
2024/10/08
Description
[CVE-2024-45278] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice
Affected system
type
Sybase platform
Patchday
2024-10
Released
on
2024/08/13
Description
[Multiple CVEs] Multiple vulnerabilities in SAP Replication Server (FOSS)
Affected system
type
SAP HANA Client
Patchday
2024-10
Released
on
2024/10/08
Description
[CVE-2024-45277] Prototype Pollution vulnerability in SAP HANA Client
Affected system
type
BI/BO platform
Patchday
2024-10
Released
on
2024/08/13
Description
[CVE-2024-41730] Missing Authentication check in SAP BusinessObjects Business Intelligence Platform
Affected system
type
BI/BO platform
Patchday
2024-10
Released
on
2024/10/08
Description
[CVE-2024-37179] Insecure File Operations vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)
Affected system
type
ABAP
Patchday
2024-10
Released
on
2024/07/09
Description
[CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-10
Released
on
2024/09/24
Description
[CVE-2024-45282] HTTP Verb Tampering in SAP S/4 HANA(Manage Bank Statements)
Affected system
type
ABAP
Patchday
2024-10
Released
on
2024/10/10
Description
Other vulnerability in service UI_PRODUCTIONVERSION
Affected system
type
SAP Commerce Cloud
Patchday
2024-09
Released
on
2024/08/13
Description
[CVE-2024-33003] Information Disclosure Vulnerability in SAP Commerce Cloud
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/08/27
Description
[CVE-2024-44121] Information Disclosure in SAP S/4 HANA (Statutory Reports)
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-41728] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-44113] Information Disclosure vulnerability in the SAP Business Warehouse (BEx Analyzer)
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-45284] Missing authorization check in SAP Student Life Cycle Management (SLcM)
Affected system
type
Java
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-44120] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-45279] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP(CRM Blueprint Application Builder Panel)
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-44112] Missing Authorization check in SAP for Oil & Gas (Transportation and Distribution)
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-44114] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
SAP Commerce Cloud
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2013-3587] Information Disclosure vulnerability in SAP Commerce Cloud
Affected system
type
Java
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-45280] Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver AS Java (Logon Application)
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[Multiple CVEs] Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-42378] Cross-Site Scripting (XSS) in eProcurement on S/4HANA
Affected system
type
ABAP
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-45286] Missing Authorization check in SAP Production and Revenue Accounting (Tobin interface)
Affected system
type
BI/BO platform
Patchday
2024-09
Released
on
2024/09/10
Description
[CVE-2024-45281] DLL hijacking vulnerability in SAP BusinessObjects Business Intelligence Platform
Affected system
type
SAP Commerce
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-41733] Information Disclosure Vulnerability in SAP Commerce
Affected system
type
BI/BO platform
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-42375] Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform
Affected system
type
Java
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-42374] XML injection in SAP BEx Web Java Runtime Export Web Service
Affected system
type
ABAP
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-42376] Multiple Missing Authorization Check vulnerabilities in SAP Shared Service Framework
Affected system
type
SAP Fiori
Patchday
2024-08
Released
on
2024/07/23
Description
[CVE-2023-30533] Prototype Pollution in SAP S/4 HANA (Manage Supply Protection)
Affected system
type
SAP Commerce
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-41735] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice
Affected system
type
ABAP
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-41732] Improper Access Control in SAP Netweaver Application Server ABAP
Affected system
type
ABAP
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-39591] Missing Authorization check in SAP Document Builder
Affected system
type
Kernel / Web Dispatcher
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-33005] Missing Authorization check in SAP NetWeaver Application Server (ABAP and Java),SAP Web Dispatcher and SAP Content Server.
Affected system
type
SAP Build Apps
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-29415] Server-Side Request Forgery vulnerability in applications built with SAP Build Apps
Affected system
type
SAP Fiori
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-41736] Information Disclosure vulnerability in SAP Permit to Work
Affected system
type
ABAP
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-41734] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-08
Released
on
2024/08/13
Description
[CVE-2024-41737] Server-Side Request Forgery (SSRF) in SAP CRM ABAP (Insights Management)
Affected system
type
SAP Enable Now
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34692] Unrestricted File upload vulnerability in SAP Enable Now
Affected system
type
SAP CRM UI
Patchday
2024-07
Released
on
2024/07/09
Description
[Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI)
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34689] Allowlisting of callback-URLs in SAP Business Workflow (WebFlow Services)
Affected system
type
SAP Commerce
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39597] Improper Authorization Checks on Early Login Composable Storefront B2B sites of SAP Commerce
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-37172] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-37171] Server-Side Request Forgery (SSRF) in SAP Transportation Management (Collaboration Portal)
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39599] Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform
Affected system
type
SAP Enable Now
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39596] Missing Authorization check vulnerability in SAP Enable Now
Affected system
type
SAP Landscape...
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39593] Information Disclosure vulnerability in SAP Landscape Management
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39594] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Business Warehouse - Business Planning and Simulation
Affected system
type
SAP GUI
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-39600] Information Disclosure vulnerability in SAP GUI for Windows
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34689] Prerequisite for Security Note 3458789
Affected system
type
Java
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34685] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Knowledge Management XMLEditor
Affected system
type
ABAP
Patchday
2024-07
Released
on
2024/07/09
Description
[CVE-2024-34689] Server-Side Request Forgery in SAP Business Workflow (WebFlow Services)
Affected system
type
Java
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34688] Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34690] Missing Authorization check in SAP Student Life Cycle Management (SLcM)
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-33001] Denial of service (DOS) in SAP NetWeaver and ABAP platform
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34683] Unrestricted file upload in SAP Document Builder (HTTP service)
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-37176] Missing Authorization check in SAP BW/4HANA Transformation and DTP
Affected system
type
BI/BO platform
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34684] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Scheduling)
Affected system
type
Java
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-28164] Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures)
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34686] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Affected system
type
ABAP
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-34691] Missing Authorization check in SAP S/4HANA (Manage Incoming Payment Files)
Affected system
type
SAP Financial Consolidation
Patchday
2024-06
Released
on
2024/06/11
Description
[CVE-2024-37177] Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33009] SQL injection vulnerability in SAP Global Label Management (GLM)
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-32733] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[Multiple CVEs] Missing Authorization Checks in SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)
Affected system
type
BI/BO platform
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33004] Insecure Storage vulnerability in SAP BusinessObjects Business Intelligence Platform (Webservices)
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-34687] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application server for ABAP and ABAP Platform
Affected system
type
BI/BO platform
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-28165] Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33002] Cross-Site Scripting (XSS) Vulnerability in SAP S/4HANA (Document Service Handler for DPS)
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33006] File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Affected system
type
Sybase platform
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33008] Memory Corruption vulnerability in SAP Replication Server
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-33007] Client-side script execution vulnerability in SAP UI5(PDFViewer)
Affected system
type
ABAP
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2024-32731] Missing Authorization check in SAP My Travel Requests
Affected system
type
SAP Commerce Cloud
Patchday
2024-05
Released
on
2024/05/14
Description
[CVE-2019-17495] Multiple vulnerabilities in SAP CX Commerce
Affected system
type
BI/BO platform
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-25646] Information Disclosure vulnerability in SAP BusinessObjects Web Intelligence
Affected system
type
SAP Business Connector
Patchday
2024-04
Released
on
2024/04/09
Description
[Multiple CVEs] Cross-Site Scripting (XSS) vulnerabilities in SAP Business Connector
Affected system
type
ABAP
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-30217] Missing Authorization check in SAP S/4 HANA (Cash Management)
Affected system
type
Kernel
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-30218] Denial of service (DOS) vulnerability in SAP NetWeaver AS ABAP and ABAP Platform
Affected system
type
Java
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-27898] Server-Side Request Forgery in SAP NetWeaver (tc~esi~esp~grmg~wshealthcheck~ear)
Affected system
type
ABAP
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-30216] Missing Authorization check in SAP S/4 HANA (Cash Management)
Affected system
type
Java
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-27899] Security misconfiguration vulnerability in SAP NetWeaver AS Java User Management Engine
Affected system
type
SAP Edge Integration
Patchday
2024-04
Released
on
2024/04/09
Description
Stack overflow vulnerability on the component images of SAP Integration Suite (EDGE INTEGRATION CELL)
Affected system
type
ABAP
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-28167] Missing Authorization check in SAP Group Reporting Data Collection (Enter Package Data)
Affected system
type
ABAP
Patchday
2024-04
Released
on
2024/04/09
Description
[CVE-2024-27901] Directory Traversal vulnerability in SAP Asset Accounting
Affected system
type
Kernel
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-27902] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP, applications based on SAPGUI for HTML (WebGUI)
Affected system
type
SAP Build Apps
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2019-10744] Code Injection vulnerability in applications built with SAP Build Apps
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-25644] Information Disclosure vulnerability in SAP NetWeaver (WSRM)
Affected system
type
BI/BO platform
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2023-50164] Path Traversal Vulnerability in SAP BusinessObjects Business Intelligence Platform (Central Management Console)
Affected system
type
HANA platform
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2023-44487 ] Denial of service (DOS) in SAP HANA XS Classic and HANA XS Advanced
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-28163] Information Disclosure vulnerability in SAP NetWeaver Process Integration (Support Web Pages)
Affected system
type
ABAP
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-27900]Missing Authorization check in SAP ABAP Platform
Affected system
type
ABAP
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-22133] Improper Access Control in SAP Fiori Front End Server
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-25645] Information Disclosure vulnerability in SAP NetWeaver (Enterprise Portal)
Affected system
type
Java
Patchday
2024-03
Released
on
2024/03/12
Description
[CVE-2024-22127] Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24739] Missing authorization check in SAP Bank Account Management
Affected system
type
Java
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24743] XXE vulnerability in SAP NetWeaver AS Java (Guided Procedures)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22131] Code Injection vulnerability in SAP ABA (Application Basis)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/01
Description
[CVE-2024-24741] Missing Authorization check in SAP Master Data Governance Material
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22130] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Affected system
type
SAP Cloud Connector
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-25642] Improper Certificate Validation in SAP Cloud Connector
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-25643] Missing authorization check in SAP Fiori app ("My Overtime Requests")
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22128] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Business Client for HTML
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22132] Code Injection vulnerability in SAP IDES Systems
Affected system
type
Kernel
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24740] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (SAP Kernel)
Affected system
type
Java
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application)
Affected system
type
SAP Enable Now
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22129] Cross-Site Scripting (XSS) vulnerability in SAP Companion
Affected system
type
Kernel
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2023-44487] Denial of service (DOS) in SAP Web Dispatcher, SAP NetWeaver Application server ABAP, and ABAP Platform
Affected system
type
BTP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA
Affected system
type
SAP Marketing
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21734] URL Redirection vulnerability in SAP Marketing (Contacts App)
Affected system
type
SAP Edge Integration
Patchday
2024-01
Released
on
2024/01/09
Description
[Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21738] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21737] Code Injection vulnerability in SAP Application Interface Framework (File Adapter)
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21735] Improper Authorization check in SAP LT Replication Server
Affected system
type
ABAP
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-21736] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)
Affected system
type
Kernel / Web Dispatcher
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-22124] Information Disclosure vulnerability in SAP NetWeaver Internet Communication Manager
Affected system
type
SAP GUI / Frontend
Patchday
2024-01
Released
on
2024/01/09
Description
[CVE-2024-22125] Information Disclosure vulnerability in Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge)