Security Advisory for January 2021 
Advisory

Today we have released the Security Advisories for SAP and the month of January 2021

 

In the month of January 2021, we would like to bring 13 security advisories to your attention.

Taking control of the SAP patch management process for the vast product portfolio offered by SAP SE is essential to maintain a steady security posture. We have reviewed the security patches released (and updated) in January 2021 and found corrections that eliminate the following attack vectors:

  • "Cross-site scripting (XSS)"
  • "Denial of Service (DoS)"
  • "External entity tunneling (XXE)"
  • "Cross-site request forgery (XSRF)"
  • "Missing authorization check"
  • "SQL Injection (read/write) Missing authentication check"
  • "Information disclosure"
  • "Code Injection"
  • "Denial of service (DOS)"

Patches released by the manufacture contain solutions for the components

  • "CEC-HCS-SEC"
  • "CEC-BAF-DOM"
  • "EPM-XLS-SEC"
  • "BC-ABA-LA"
  • "FIN-FSCM-IHC"
  • "BI-RA-WBI-FE"
  • "CA-VE-VEV"
  • "FS-BA-SD-PO"
  • "BW-WHM-DST-DBC"
  • "BW-BEX-OT-DBIF"
  • "BC-FES-GUI"
  • "FIN-FIO-CLM"
  • "MDM-FN-MDS-SEC"

View all advisories of January 2021.

  • Share with:
ABEX logo

SecurityBridge helps in prioritizing SAP patches, updates and the remediation strategies essential for preventing the disruption of vital business systems. We help businesses in making their SAP systems more secure.

SecurityBridge

© Copyright 2024 by SecurityBridge GmbH

v35.0