We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.
We hope you enjoy using it!
This time we found critical correction advisiories. We count 13 and the highest CVSS score is 9.1.
Severity
SAP© Security advisories 13
System Types
Affected SAP© system types
Affected system
type
Java
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application)
Affected system
type
Kernel
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24740] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (SAP Kernel)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22132] Code Injection vulnerability in SAP IDES Systems
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22128] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Business Client for HTML
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-25643] Missing authorization check in SAP Fiori app ("My Overtime Requests")
Affected system
type
SAP Cloud Connector
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-25642] Improper Certificate Validation in SAP Cloud Connector
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22130] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/01
Description
[CVE-2024-24741] Missing Authorization check in SAP Master Data Governance Material
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22131] Code Injection vulnerability in SAP ABA (Application Basis)
Affected system
type
Java
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24743] XXE vulnerability in SAP NetWeaver AS Java (Guided Procedures)
Affected system
type
SAP Enable Now
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-22129] Cross-Site Scripting (XSS) vulnerability in SAP Companion
Affected system
type
ABAP
Patchday
2024-02
Released
on
2024/02/13
Description
[CVE-2024-24739] Missing authorization check in SAP Bank Account Management