We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 18 and the highest CVSS score is 9.8.

 

Severity
SAP© Security advisories 18
 System Types
Affected SAP© system types

 

2928570
CVSS
9.8

Affected system type Java
Patchday 2020-06
Released on 2020/06/09
Description Ghostcat' Apache Tomcat AJP Vulnerability in SAP Liquidity Management for Banking
2918924
CVSS
9.8

Affected system type SAP Cloud Commerce
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6265] Use of Hard-coded Credentials in SAP Commerce and SAP Commerce Datahub
2906366
CVSS
8.6

Affected system type SAP Cloud Commerce
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6264] Information Disclosure in SAP Commerce
2931391
CVSS
8.2

Affected system type Java
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6271] Missing XML Validation in SAP Solution Manager (Problem Context Manager)
2912939
CVSS
7.6

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6275] Server Side Request Forgery vulnerability in SAP NetWeaver AS ABAP
2878568
CVSS
6.9

Affected system type Java
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6263] Authentication Bypass in Standalone Clients connecting to SAP NetWeaver AS Java via P4 Protocol
2916562
CVSS
6.5

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6270] Missing Authorization check in SAP Netweaver AS ABAP (Banking Services)
2918762
CVSS
6.5

Affected system type Adobe LiveCycle Designer
Patchday 2020-06
Released on 2020/06/09
Description Multiple vulnerabilities in Adobe LiveCycle Designer 11.0
2915126
CVSS
6.5

Affected system type Java
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6260] Incomplete XML Validation in SAP Solution Manager (Trace Analysis)
2540180
CVSS
6.3

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description Switchable Authorization checks for RFC in Environment, Health & Safety
2878935
CVSS
6.1

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6246] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP ( Business Server Pages Test Application SBSPEXT_TABLE)
2911687
CVSS
5.4

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA
2911704
CVSS
5.4

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA
2906996
CVSS
5.4

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6268] Missing authorization check in SAP ERP (Statutory Reporting for Insurance Companies)
2908382
CVSS
4.4

Affected system type SAP Business One
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6239] Information Disclosure in SAP Business One (Backup Service)
2923035
CVSS
4.4

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI
2911267
CVSS
4.3

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description Update 1 to Security Note 2752614 - [CVE-2019-0319] Content Injection Vulnerability in SAP Gateway
2905836
CVSS
4.3

Affected system type BI/BO platform
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6269] Information Disclosure in SAP Business Objects Business Intelligence Platform