We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.
We hope you enjoy using it!
× Hey there! Glad you made it.
We have found 10 security advices for you to review.

 

 Severity
SAP© Security advisories 10
 System Types
Affected SAP© system types

 

Related note
3460407
CVSS
7.5

Affected system type
Java
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-34688] Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)

 

Related note
3457265
CVSS
5.4

Affected system type
ABAP
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-34690] Missing Authorization check in SAP Student Life Cycle Management (SLcM)

 

Related note
3453170
CVSS
6.5

Affected system type
ABAP
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-33001] Denial of service (DOS) in SAP NetWeaver and ABAP platform

 

Related note
3459379
CVSS
6.5

Affected system type
ABAP
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-34683] Unrestricted file upload in SAP Document Builder (HTTP service)

 

Related note
3465455
CVSS
5.5

Affected system type
ABAP
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-37176] Missing Authorization check in SAP BW/4HANA Transformation and DTP

 

Related note
3441817
CVSS
3.7

Affected system type
BI/BO platform
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-34684] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Scheduling)

 

Related note
3425571
CVSS
5.3

Affected system type
Java
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-28164] Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures)

 

Related note
3465129
CVSS
6.1

Affected system type
ABAP
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-34686] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)

 

Related note
3466175
CVSS
6.5

Affected system type
ABAP
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-34691] Missing Authorization check in SAP S/4HANA (Manage Incoming Payment Files)

 

Related note
3457592
CVSS
8.1

Affected system type
SAP Financial Consolidation
Patchday
2024-06
Released on
2024/06/11

Description
[CVE-2024-37177] Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation

 

 
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2024 by SecurityBridge GmbH

v35.0