We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.
We hope you enjoy using it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 10 and the highest CVSS score is 9.1.

 

 Severity
SAP© Security advisories 10
 System Types
Affected SAP© system types

 

Related note
3413475
CVSS
9.1

Affected system type
SAP Edge Integration
Patchday
2024-01
Released on
2024/01/09

Description
[Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell

 

Related note
3411869
CVSS
8.4

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21737] Code Injection vulnerability in SAP Application Interface Framework (File Adapter)

 

Related note
3260667
CVSS
6.4

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21736] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)

 

Related note
3392626
CVSS
4.1

Affected system type
Kernel / Web Dispatcher
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-22124] Information Disclosure vulnerability in SAP NetWeaver Internet Communication Manager

 

Related note
3407617
CVSS
7.3

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21735] Improper Authorization check in SAP LT Replication Server

 

Related note
3387737
CVSS
4.1

Affected system type
ABAP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21738] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform

 

Related note
3190894
CVSS
3.7

Affected system type
SAP Marketing
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-21734] URL Redirection vulnerability in SAP Marketing (Contacts App)

 

Related note
3412456
CVSS
9.1

Affected system type
BTP
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA

 

Related note
3389917
CVSS
7.5

Affected system type
Kernel
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2023-44487] Denial of service (DOS) in SAP Web Dispatcher, SAP NetWeaver Application server ABAP, and ABAP Platform

 

Related note
3386378
CVSS
7.4

Affected system type
SAP GUI / Frontend
Patchday
2024-01
Released on
2024/01/09

Description
[CVE-2024-22125] Information Disclosure vulnerability in Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge)

 

 
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2024 by SecurityBridge GmbH

v35.0