We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.
We hope you enjoy using it!
× Yikes, there is work to do!
This time we found critical correction advisiories. We count 10 and the highest CVSS score is 9.4.

 

 Severity
SAP© Security advisories 10
 System Types
Affected SAP© system types

 

Related note
3410615
CVSS
7.5

Affected system type
HANA platform
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2023-44487 ] Denial of service (DOS) in SAP HANA XS Classic and HANA XS Advanced

 

Related note
3428847
CVSS
5.3

Affected system type
Java
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-25645] Information Disclosure vulnerability in SAP NetWeaver (Enterprise Portal)

 

Related note
3417399
CVSS
4.6

Affected system type
ABAP
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-22133] Improper Access Control in SAP Fiori Front End Server

 

Related note
3419022
CVSS
4.3

Affected system type
ABAP
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-27900]Missing Authorization check in SAP ABAP Platform

 

Related note
3434192
CVSS
5.3

Affected system type
Java
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-28163] Information Disclosure vulnerability in SAP NetWeaver Process Integration (Support Web Pages)

 

Related note
3377979
CVSS
5.4

Affected system type
Kernel
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-27902] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP, applications based on SAPGUI for HTML (WebGUI)

 

Related note
3414195
CVSS
7.2

Affected system type
BI/BO platform
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2023-50164] Path Traversal Vulnerability in SAP BusinessObjects Business Intelligence Platform (Central Management Console)

 

Related note
3425682
CVSS
5.3

Affected system type
Java
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-25644] Information Disclosure vulnerability in SAP NetWeaver (WSRM)

 

Related note
3425274
CVSS
9.4

Affected system type
SAP Build Apps
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2019-10744] Code Injection vulnerability in applications built with SAP Build Apps

 

Related note
3433192
CVSS
9.1

Affected system type
Java
Patchday
2024-03
Released on
2024/03/12

Description
[CVE-2024-22127] Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)

 

 
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2024 by SecurityBridge GmbH

v35.0