We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 179 and the highest CVSS score is 10.0.

 

Severity
SAP© Security advisories 179
 System Types
Affected SAP© system types

 

3131258
CVSS
10.0

Affected system type SAP HANA Platform
Patchday 2021-12
Released on 2021/12/16
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP HANA XSA
3131397
CVSS
10.0

Affected system type SAP HANA Platform
Patchday 2021-12
Released on 2021/12/17
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit
3132162
CVSS
10.0

Affected system type SAP API Management
Patchday 2021-12
Released on 2021/12/24
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP API Management (Tenant Cloning Tool)
3132744
CVSS
10.0

Affected system type SAP BTP Kyma runtime
Patchday 2021-12
Released on 2021/12/21
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Kyma
3131047
CVSS
10.0

Affected system type Any
Patchday 2021-12
Released on 2021/12/15
Description [CVE-2021-44228] Central Security Note for Remote Code Execution vulnerability associated with Apache Log4j 2 component
3132909
CVSS
10.0

Affected system type SAP Edge Services 
Patchday 2021-12
Released on 2021/12/24
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services On Premise Edition
3130578
CVSS
10.0

Affected system type SAP BTP Cloud Foundry runtime
Patchday 2021-12
Released on 2021/12/21
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Cloud Foundry
3132922
CVSS
10.0

Affected system type SAP Edge Services 
Patchday 2021-12
Released on 2021/12/21
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Internet of Things Edge Platform
3133772
CVSS
10.0

Affected system type SAP Customer Checkout
Patchday 2021-12
Released on 2021/12/22
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Customer Checkout
3132964
CVSS
10.0

Affected system type SAP Enable Now
Patchday 2021-12
Released on 2021/12/23
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Enable Now Manager
3109577
CVSS
9.9

Affected system type SAP Commerce
Patchday 2021-12
Released on 2021/12/14
Description Code Execution vulnerability in SAP Commerce, localization for China
3119365
CVSS
9.9

Affected system type ABAP
Patchday 2021-12
Released on 2021/12/14
Description [CVE-2021-44231] Code Injection vulnerability in SAP ABAP Server & ABAP Platform (Translation Tools)
3130521
CVSS
9.9

Affected system type Java
Patchday 2021-12
Released on 2021/12/16
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration
3132198
CVSS
9.8

Affected system type SAP Landscape...
Patchday 2021-12
Released on 2021/12/20
Description [CVE-2019-17571] Code Injection vulnerability in SAP Landscape Management
3132822
CVSS
9.0

Affected system type SAP HANA Platform
Patchday 2021-12
Released on 2021/12/21
Description Update 1 to Security Note 3131397 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit
3102769
CVSS
8.8

Affected system type Java
Patchday 2021-12
Released on 2021/12/14
Description [CVE-2021-42063] Cross-Site Scripting (XSS) vulnerability in SAP Knowledge Warehouse
3114134
CVSS
8.8

Affected system type SAP Commerce
Patchday 2021-12
Released on 2021/12/14
Description [CVE-2021-42064] SQL Injection vulnerability in SAP Commerce
3123196
CVSS
8.4

Affected system type ABAP
Patchday 2021-12
Released on 2021/12/14
Description [CVE-2021-44235] Code Injection vulnerability in utility class for SAP NetWeaver AS ABAP
3131824
CVSS
8.0

Affected system type SAP Connected Health platform
Patchday 2021-12
Released on 2021/12/20
Description [CVE-2021-44228] Log4j Vulnerability in Connected Health Platform 2.0 - Fhirserver
3132074
CVSS
8.0

Affected system type SAP Cloud for Customer
Patchday 2021-12
Released on 2021/12/23
Description [CVE-2021-44228] Code Injection vulnerability in Cloud for Customer Lotus Notes PlugIn
3124094
CVSS
7.7

Affected system type ABAP
Patchday 2021-12
Released on 2021/12/14
Description [CVE-2021-44232] Directory Traversal vulnerability in SAF-T Framework
3113593
CVSS
7.5

Affected system type SAP Commerce
Patchday 2021-12
Released on 2021/12/14
Description Denial of service (DOS) in SAP Commerce
3107332
CVSS
6.6

Affected system type SAP Landscape Management
Patchday 2021-12
Released on 2021/12/14
Description Missing Authorization Check in SAP Landscape Management
2661033
CVSS
6.3

Affected system type ABAP
Patchday 2021-12
Released on 2021/11/23
Description Missing Authorization check in RFC enabled function modules in SRM
2460948
CVSS
5.3

Affected system type ABAP
Patchday 2021-12
Released on 2021/11/23
Description Missing Authorization Check in Vehicle Management System
2484231
CVSS
4.3

Affected system type ABAP
Patchday 2021-12
Released on 2021/12/14
Description Missing Authorization Check in DIMP Industry Solution (Equipment and Tools Management & Bills of Services)
3121165
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-12
Released on 2021/12/14
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3103677
CVSS
4.1

Affected system type BI/BO platform
Patchday 2021-12
Released on 2021/12/14
Description [CVE-2021-42061] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform (Web Intelligence)
3051005
CVSS
3.5

Affected system type SAP UI5
Patchday 2021-12
Released on 2021/12/14
Description Cross-Site Scripting (XSS) Vulnerability in SAP Fiori Launchpad
3132204
CVSS
3.1

Affected system type Java
Patchday 2021-12
Released on 2021/12/16
Description Update 1 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration
3080816
CVSS
2.4

Affected system type ABAP
Patchday 2021-12
Released on 2021/12/14
Description [CVE-2021-44233] Missing Authorization check in GRC Access Control
3099776
CVSS
9.6

Affected system type Kernel
Patchday 2021-11
Released on 2021/11/09
Description [CVE-2021-40501] Missing Authorization check in ABAP Platform Kernel
3110328
CVSS
8.3

Affected system type SAP Commerce
Patchday 2021-11
Released on 2021/11/09
Description [CVE-2021-40502] Missing Authorization check in SAP Commerce
2827086
CVSS
7.9

Affected system type SAP FRP
Patchday 2021-11
Released on 2021/11/09
Description Several security vulnerabilities in FRP 5.4.0 and FR Engine 5.4.0
3080106
CVSS
6.8

Affected system type SAP GUI / Frontend
Patchday 2021-11
Released on 2021/11/09
Description [CVE-2021-40503] Information Disclosure in SAP GUI for Windows
3104456
CVSS
6.5

Affected system type ABAP
Patchday 2021-11
Released on 2021/11/09
Description [CVE-2021-42062] Missing Authorization check in SAP ERP HCM
2607126
CVSS
6.3

Affected system type Java
Patchday 2021-11
Released on 2021/11/09
Description Cross-Site Request Forgery vulnerability in Enterprise Services Repository of SAP Process Integration
3105728
CVSS
4.9

Affected system type ABAP
Patchday 2021-11
Released on 2021/11/09
Description [CVE-2021-40504] Leverage of Permission in SAP NetWeaver Application Server for ABAP and ABAP Platform
3106859
CVSS
4.3

Affected system type ABAP
Patchday 2021-11
Released on 2021/11/09
Description URL Redirection vulnerability in Offer Management
3101406
CVSS
9.8

Affected system type Java
Patchday 2021-10
Released on 2021/10/12
Description Potential XML External Entity Injection Vulnerability in SAP Environmental Compliance
3089438
CVSS
9.1

Affected system type ABAP
Patchday 2021-10
Released on 2021/09/20
Description Missing transaction start (AU3) entries in the Security Audit Log
3097887
CVSS
9.1

Affected system type ABAP
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-38178] Improper Authorization in SAP NetWeaver AS ABAP and ABAP Platform
3077635
CVSS
7.8

Affected system type SAP Success Factors
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-40498] Denial of service (DOS) in the SAP SuccessFactors Mobile Application for Android devices
3074693
CVSS
6.9

Affected system type BI/BO platform
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-40500] Missing XML Validation in SAP BusinessObjects Business Intelligence Platform (Crystal Reports)
3074819
CVSS
6.7

Affected system type SAP Business One
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-38179] Information Disclosure in SAP Business One
3079427
CVSS
6.5

Affected system type SAP Business One
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-38180] CSV Injection in SAP Business One
3080710
CVSS
6.5

Affected system type ABAP
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-38181] Denial of service (DOS) in SAP NetWeaver AS ABAP and ABAP Platform
3100882
CVSS
6.4

Affected system type SAP Cloud Print Manager
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-40499] Code Injection vulnerability for SAP NetWeaver Application Server for ABAP (SAP Cloud Print Manager and SAPSprint)
3055347
CVSS
6.1

Affected system type SAP UI5
Patchday 2021-10
Released on 2021/10/12
Description Cross-Site Scripting (XSS) vulnerability in SAPUI5
2988962
CVSS
5.4

Affected system type ABAP
Patchday 2021-10
Released on 2021/09/28
Description Cross-Site Request Forgery (CSRF) vulnerability for S/4HANA OP2020, OP1909 in Import Financial Plan Data
2988956
CVSS
5.4

Affected system type ABAP
Patchday 2021-10
Released on 2021/09/28
Description Cross-Site Request Forgery (CSRF) vulnerability in S/4HANA OP2020, OP1909 in Import Financial Plan Data
3084937
CVSS
5.4

Affected system type ABAP
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-38183] Cross-Site Scripting (XSS) vulnerability in cms Service of SAP NetWeaver
3099011
CVSS
5.3

Affected system type ABAP
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-40495] Denial of Service (DOS) in SAP NetWeaver Application Server for ABAP and ABAP Platform
2655294
CVSS
5.3

Affected system type ABAP
Patchday 2021-10
Released on 2021/10/12
Description Missing Authorization check in SCM BAPIs
3087254
CVSS
4.3

Affected system type ABAP
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-40496] Improper Access Control in SAP NetWeaver AS ABAP and ABAP Platform
3098917
CVSS
4.3

Affected system type BI/BO platform
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-40497] Information Disclosure in SAP BusinessObjects Analysis (edition for OLAP)
3078609
CVSS
10.0

Affected system type Java
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-37535] Missing Authorization check in SAP NetWeaver Application Server for Java (JMS Connector Service)
3089831
CVSS
9.9

Affected system type ABAP
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38176] SQL Injection vulnerability in SAP NZDT Mapping Table Framework
3084487
CVSS
9.9

Affected system type Java
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38163] Unrestricted File Upload vulnerability in SAP NetWeaver (Visual Composer 7.0 RT)
3081888
CVSS
9.9

Affected system type Java
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-37531] Code Injection vulnerability in SAP NetWeaver Knowledge Management (XMLForms)
3073891
CVSS
9.6

Affected system type BCM platform
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-33672] Multiple vulnerabilities in SAP Contact Center
3080567
CVSS
8.9

Affected system type Kernel
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38162] HTTP Request Smuggling in SAP Web Dispatcher
3051787
CVSS
7.5

Affected system type ABAP Java HANA platform
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38177] Null Pointer Dereference vulnerability in SAP CommonCryptoLib
3082500
CVSS
6.5

Affected system type ABAP
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38175] Information Disclosure in SAP Analysis for Microsoft Office
3069032
CVSS
6.5

Affected system type SAP Business One
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-33685] Directory Traversal vulnerability in SAP Business One
3060621
CVSS
6.1

Affected system type SAP GUI / Frontend
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38150] Information disclosure in SAP Business Client
3068582
CVSS
5.4

Affected system type ABAP
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38164] Missing Authorization check in in SAP ERP Financial Accounting / RFOPENPOSTING_FR
3055180
CVSS
5.4

Affected system type BI/BO platform
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-33679] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI Workspace)
3070138
CVSS
5.3

Affected system type SAP Business One
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-33686] Information Disclosure in SAP Business One
3082219
CVSS
4.8

Affected system type Java
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-21489] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
2308378
CVSS
4.3

Affected system type ABAP
Patchday 2021-09
Released on 2021/09/14
Description Missing Authorization check in Financial Accounting
3087791
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38174] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3069882
CVSS
4.3

Affected system type SAP Business One
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-33688] SQL Injection vulnerability in SAP Business One
3075546
CVSS
4.3

Affected system type SAP Business One
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-37532] Directory Listing Enabled in SAP Business One
3068337
CVSS
3.5

Affected system type ABAP
Patchday 2021-09
Released on 2021/09/14
Description Reverse tabnabbing vulnerability in SAP Marketing Lead Nurture Stream
3071984
CVSS
9.9

Affected system type SAP Business One
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33698] Unrestricted File Upload vulnerability in SAP Business One
3072955
CVSS
9.9

Affected system type Java
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33690] Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure (Component Build Service)
3078312
CVSS
9.1

Affected system type ABAP
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33701] SQL Injection vulnerability in SAP NZDT Row Count Reconciliation
3057378
CVSS
8.8

Affected system type Kernel
Patchday 2021-08
Released on 2021/08/10
Description Missing Authentication check in SAP Web Dispatcher
3073681
CVSS
8.3

Affected system type Java
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33702] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3072920
CVSS
8.3

Affected system type Java
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33703] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3074844
CVSS
8.1

Affected system type Java
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33705] Server-Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Enterprise Portal
3067219
CVSS
7.6

Affected system type SAP Fiori Client Android
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33699] Task Hijacking in SAP Fiori Client Native Mobile for Android
3073325
CVSS
7.0

Affected system type SAP Business One
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33700] Missing Authentication check in SAP Business One
3073450
CVSS
6.9

Affected system type Java
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33691] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Development Infrastructure (Notification Service)
3058553
CVSS
6.8

Affected system type SAP Cloud Connector
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33695] Multiple Vulnerabilities in SAP Cloud Connector
2659604
CVSS
6.4

Affected system type ABAP
Patchday 2021-08
Released on 2021/07/27
Description Cross-Site Scripting (XSS) Vulnerability in BSP application CRM_CM
3002517
CVSS
6.3

Affected system type ABAP
Patchday 2021-08
Released on 2021/06/08
Description [CVE-2021-21473] Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform
2675775
CVSS
6.3

Affected system type ABAP
Patchday 2021-08
Released on 2021/08/10
Description Switchable Authorization checks for RFC in CRM Middleware
3078072
CVSS
6.3

Affected system type SAP Business One
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33704] Missing Authorization Check in SAP Business One (Service Layer)
3076399
CVSS
6.1

Affected system type Java
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33707] URL Redirection vulnerability in SAP NetWeaver (Knowledge Management)
3062085
CVSS
5.4

Affected system type BI/BO platform
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33696] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Crystal Report)
3063048
CVSS
4.7

Affected system type BI/BO platform
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33697] Reverse Tabnabbing in SAP BusinessObjects Business Intelligence Platform (SAP UI5)
3007182
CVSS
9.0

Affected system type ABAP
Patchday 2021-07
Released on 2021/06/08
Description [CVE-2021-27610] Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform
3059446
CVSS
7.6

Affected system type Java
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33671] Missing Authorization check in SAP NetWeaver Guided Procedures
3056652
CVSS
7.5

Affected system type Java
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33670] Denial of Service (DoS) in SAP NetWeaver AS for Java (Http Service)
3066316
CVSS
6.8

Affected system type ABAP
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33676] Missing authorization check in SAP CRM ABAP
3048657
CVSS
6.5

Affected system type ABAP
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33678] Code Injection vulnerability in SAP NetWeaver AS ABAP (Reconciliation Framework)
3044754
CVSS
6.5

Affected system type ABAP
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33677] Information Disclosure in SAP NetWeaver AS ABAP and ABAP Platform
3000663
CVSS
5.4

Affected system type Kernel
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33683] HTTP Request Smuggling in SAP Web Dispatcher and Internet Communication Manager
3053403
CVSS
5.4

Affected system type SAP Lumira Server
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33682] Cross-Site Scripting (XSS) vulnerability in SAP Lumira Server
3032624
CVSS
5.3

Affected system type Kernel
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33684] Memory Corruption in SAP NetWeaver AS ABAP and ABAP Platform
3059764
CVSS
4.5

Affected system type Java
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33687] Information Disclosure in SAP NetWeaver AS for Java (Enterprise Portal)
3044751
CVSS
4.3

Affected system type BI/BO platform
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33667] Information Disclosure in SAP Business Objects Web Intelligence (BI Launchpad)
3067890
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-07
Released on 2021/07/13
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3038594
CVSS
3.5

Affected system type Java
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33689] Insufficient Logging in SAP NetWeaver AS for JAVA (Administrator)
3053066
CVSS
8.7

Affected system type Java
Patchday 2021-06
Released on 2021/06/08
Description [CVE-2021-27635] Missing XML Validation in SAP NetWeaver AS for JAVA
3030961
CVSS
6.4

Affected system type Java
Patchday 2021-06
Released on 2021/06/08
Description [CVE-2021-27615] Cross-Site Scripting (XSS) vulnerability in SAP Manufacturing Execution
3049879
CVSS
5.9

Affected system type SAP Enable Now
Patchday 2021-06
Released on 2021/06/08
Description [CVE-2021-27637] Information Disclosure in SAP Enable Now (SAP Workforce Performance Builder - Manager)
3021050
CVSS
5.9

Affected system type Internet Graphics Service
Patchday 2021-06
Released on 2021/06/08
Description [Multiple CVEs] Memory Corruption vulnerability in SAP Internet Graphics Service
3030604
CVSS
5.8

Affected system type ABAP
Patchday 2021-06
Released on 2021/06/08
Description [CVE-2021-33663] Plaintext Injection in SAP NetWeaver AS for ABAP
3028370
CVSS
5.4

Affected system type ABAP
Patchday 2021-06
Released on 2021/06/08
Description [CVE-2021-33665] Cross-Site Scripting (XSS) vulnerability within SAP NetWeaver AS ABAP (Applications based on SAP GUI for HTML)
3025604
CVSS
5.4

Affected system type ABAP
Patchday 2021-06
Released on 2021/06/08
Description [CVE-2021-33664] Cross-Site Scripting (XSS) vulnerability within SAP NetWeaver AS ABAP (Applications based on Web Dynpro ABAP)
2985562
CVSS
4.7

Affected system type SAP Commerce Cloud
Patchday 2021-06
Released on 2021/06/08
Description [CVE-2021-33666] Cross-Site Scripting (XSS) in SAP Commerce Cloud
2999590
CVSS
4.3

Affected system type ABAP
Patchday 2021-06
Released on 2021/05/25
Description Incomplete authorization checks for import of environmental data
3046610
CVSS
8.2

Affected system type ABAP
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27611] Code Injection vulnerability in SAP NetWeaver AS ABAP
3049661
CVSS
7.8

Affected system type SAP Business One
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27616] Multiple vulnerabilities in SAP Business One, version for SAP HANA (Business-One-Hana-Chef-Cookbook)
3049755
CVSS
7.8

Affected system type SAP Business One
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27613] Information Disclosure in SAP Business One (Chef business-one-cookbook)
3039818
CVSS
6.5

Affected system type SAP Commerce Cloud
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27619] Information Disclosure in SAP Commerce (Backoffice search)
2114798
CVSS
6.3

Affected system type ABAP
Patchday 2021-05
Released on 2021/04/27
Description Unauthorized use of application functions in SAP GUI for HTML
2745860
CVSS
5.3

Affected system type Java
Patchday 2021-05
Released on 2021/05/11
Description Information Disclosure in Enterprise Services Repository of SAP Process Integration
3012021
CVSS
4.9

Affected system type Java
Patchday 2021-05
Released on 2021/05/11
Description [Multiple CVEs] Multiple vulnerabilities in SAP Process Integration (Integration Builder Framework)
2904569
CVSS
4.6

Affected system type SAP CRM UI
Patchday 2021-05
Released on 2021/04/27
Description Cross-Site Request Forgery (CSRF) vulnerability in SAP CRM WebClient UI
3023078
CVSS
3.4

Affected system type SAP GUI / Frontend
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27612] SAP GUI for Windows is vulnerable to redirect users to an untrusted website
3040210
CVSS
9.9

Affected system type SAP Commerce / SAP...
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27602] Remote Code Execution vulnerability in Source Rules of SAP Commerce
3017908
CVSS
8.3

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-21482] Information Disclosure in SAP NetWeaver Master Data Management
3017823
CVSS
8.2

Affected system type SAP Solution Manager
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-21483] Information Disclosure in SAP Solution Manager
3039649
CVSS
7.5

Affected system type SAP GUI / Frontend
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27608] Unquoted Search Path in SAPSetup
3001824
CVSS
7.4

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-21485] Information Disclosure in SAP NetWeaver AS for Java (Telnet Commands)
3027937
CVSS
6.5

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27598] Improper Access Control in SAP NetWeaver AS for Java (Customer Usage Provisioning Servlet)
3036436
CVSS
6.5

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27604] Potential XXE Vulnerability in SAP Process Integration (ESR Java Mappings)
3028729
CVSS
6.5

Affected system type ABAP
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27603] Denial of Service (DoS) in SAP NetWeaver AS of ABAP
3012277
CVSS
6.5

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27599] Information Disclosure in SAP Process Integration (Integration Builder Framework)
3024414
CVSS
6.4

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27600 ] Cross-Site Scripting (XSS) vulnerability in SAP Manufacturing Execution (System Rules)
3005802
CVSS
5.4

Affected system type ABAP
Patchday 2021-04
Released on 2021/03/23
Description Cross-Site Request Forgery (CSRF) vulnerability in S/4HANA Finance for advanced payment management
2963592
CVSS
5.4

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27601] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java (Applications based on HTMLB for Java)
2911863
CVSS
5.3

Affected system type BI/BO platform
Patchday 2021-04
Released on 2021/04/13
Description Information Disclosure in BOE/CMC application
3036679
CVSS
5.3

Affected system type ABAP
Patchday 2021-04
Released on 2021/04/13
Description Update 1 to Security Note 1576763: Potential information disclosure relating to usernames
3030948
CVSS
4.6

Affected system type SAP Solution Manager...
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27609] Missing Authorization check in SAP Focused RUN
2818965
CVSS
4.6

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description Clickjacking vulnerability in Runtime Workbench of SAP Process Integration
3025054
CVSS
4.3

Affected system type ABAP
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27605 ] Missing Authorization check in HCM Travel Management Fiori Apps V2
3025637
CVSS
4.3

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-21492] Content spoofing in NetWeaver AS Java HTTP Service
3035472
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-04
Released on 2021/03/18
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3022622
CVSS
9.9

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence
3022422
CVSS
9.6

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21481] Missing Authorization Check in SAP NetWeaver AS JAVA (MigrationService)
3017378
CVSS
7.7

Affected system type SAP HANA Platform
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21484] Possible authentication bypass in SAP HANA LDAP scenarios
3023778
CVSS
6.8

Affected system type ABAP
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21487] Missing Authorization Check in Payment Engine
3007888
CVSS
6.8

Affected system type ABAP
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21486] Missing Authorization check in SAP Enterprise Financial Services( Bank Customer Accounts )
2983436
CVSS
6.5

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21488] Insecure deserialisation in SAP NetWeaver Knowledge Management
2475705
CVSS
6.3

Affected system type ABAP
Patchday 2021-03
Released on 2021/02/23
Description Switchable Authorization checks for RFC in In House Cash
2978151
CVSS
4.7

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description Reverse tabnabbing issue in Unified Rendering based frameworks in NetWeaver Application Server Java
2977001
CVSS
4.7

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on HTMLB for Java)
2976947
CVSS
4.7

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21491] Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on Web Dynpro Java)
3027767
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-27592] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3027758
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-03
Released on 2021/03/09
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3014121
CVSS
9.9

Affected system type SAP Commerce Cloud
Patchday 2021-02
Released on 2021/02/09
Description [CVE-2021-21477] Remote Code Execution vulnerability in SAP Commerce
2998173
CVSS
6.3

Affected system type SAP Netweaver
Patchday 2021-02
Released on 2021/02/09
Description [CVE-2021-21472] Server password not set during installation of SAP NetWeaver Master Data Management 7.1
2990992
CVSS
5.4

Affected system type ABAP
Patchday 2021-02
Released on 2021/02/09
Description Missing Authorization Checks in the Monitor Data and My Data Collections Apps
2835240
CVSS
5.4

Affected system type Java
Patchday 2021-02
Released on 2021/02/09
Description Clickjacking vulnerability in Cloud Integration Content of SAP Process Integration
2935791
CVSS
5.4

Affected system type BI/BO platform
Patchday 2021-02
Released on 2021/02/09
Description [CVE-2021-21444] Clickjacking vulnerability in SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad)
2974582
CVSS
4.7

Affected system type ABAP
Patchday 2021-02
Released on 2021/02/09
Description [CVE-2021-21478] Reverse Tabnabbing vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP)
2973428
CVSS
4.7

Affected system type Kernel
Patchday 2021-02
Released on 2021/02/09
Description Reverse Tabnabbing vulnerability within SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML)
2994289
CVSS
4.1

Affected system type ABAP
Patchday 2021-02
Released on 2021/02/09
Description Reverse Tabnabbing vulnerability within SAP CRM WebClient UI
2992154
CVSS
4.1

Affected system type SAP HANA Platform
Patchday 2021-02
Released on 2021/02/09
Description [CVE-2021-21474] SAML Assertion Signature MD5 Digest Algorithm Vulnerability in SAP HANA Database
3000897
CVSS
4.0

Affected system type Java
Patchday 2021-02
Released on 2021/02/09
Description [CVE-2021-21475] Directory Traversal vulnerability in SAP NetWeaver Master Data Management 7.1
2818963
CVSS
0.0

Affected system type Java
Patchday 2021-02
Released on 2021/02/09
Description Clickjacking vulnerability in Adapter Runtime of SAP Process Integration
2999854
CVSS
9.9

Affected system type ABAP
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21466] Code Injection in SAP Business Warehouse and SAP BW/4HANA
2986980
CVSS
9.9

Affected system type ABAP
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21465] Multiple vulnerabilities in SAP Business Warehouse (Database Interface)
3001373
CVSS
8.9

Affected system type Cloud Foundry
Patchday 2021-01
Released on 2020/12/22
Description Information Disclosure in Central Order
3000306
CVSS
7.5

Affected system type ABAP
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21446] Denial of service (DOS) in SAP NetWeaver AS ABAP and ABAP Platform
2743329
CVSS
6.3

Affected system type ABAP
Patchday 2021-01
Released on 2021/01/12
Description Switchable authorization checks for RFC module in In-House-Cash.
2665387
CVSS
5.5

Affected system type ABAP
Patchday 2021-01
Released on 2021/01/12
Description Cross-Site Request Forgery (CSRF) vulnerability in Cash Management
2965154
CVSS
5.4

Affected system type BI/BO platform
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21447] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)
2984034
CVSS
5.4

Affected system type SAP Commerce Cloud
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21445] Header Manipulation vulnerability in SAP Commerce Cloud
2992269
CVSS
5.3

Affected system type SAP GUI / Frontend
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21448] Information Disclosure in SAP GUI for Windows
2993032
CVSS
5.3

Affected system type Java
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21469] Information Disclosure in SAP NetWeaver Master Data Management
3002617
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-01
Released on 2021/01/12
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3008422
CVSS
4.3

Affected system type ABAP
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21467] Missing Authorization check in SAP Banking Services (Generic Market Data)
3000291
CVSS
3.6

Affected system type Analysis for Office
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21470] XML External Entity vulnerability in SAP EPM add-in