We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 12 and the highest CVSS score is 9.9.

 

Severity
SAP© Security advisories 12
 System Types
Affected SAP© system types

 

3022622
CVSS
9.9

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence
3022422
CVSS
9.6

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21481] Missing Authorization Check in SAP NetWeaver AS JAVA (MigrationService)
3017378
CVSS
7.7

Affected system type SAP HANA Platform
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21484] Possible authentication bypass in SAP HANA LDAP scenarios
3023778
CVSS
6.8

Affected system type ABAP
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21487] Missing Authorization Check in Payment Engine
3007888
CVSS
6.8

Affected system type ABAP
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21486] Missing Authorization check in SAP Enterprise Financial Services( Bank Customer Accounts )
2983436
CVSS
6.5

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21488] Insecure deserialisation in SAP NetWeaver Knowledge Management
2475705
CVSS
6.3

Affected system type ABAP
Patchday 2021-03
Released on 2021/02/23
Description Switchable Authorization checks for RFC in In House Cash
2978151
CVSS
4.7

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description Reverse tabnabbing issue in Unified Rendering based frameworks in NetWeaver Application Server Java
2976947
CVSS
4.7

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21491] Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on Web Dynpro Java)
2977001
CVSS
4.7

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on HTMLB for Java)
3027758
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-03
Released on 2021/03/09
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3027767
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-27592] Improper Input Validation in SAP 3D Visual Enterprise Viewer