We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.
We hope you enjoy using it!
We have found 9 security advices for you to review.
Severity
SAP© Security advisories 9
System Types
Affected SAP© system types
Affected system
                                                            type
                                                        
                                                            ABAP
                                                    
                                                
                                                        Patchday
2021-05
                                                    
                                                Released
                                                            on
2021/05/11
                                                    
                                                Description
                                                        [CVE-2021-27611] Code Injection vulnerability in SAP NetWeaver AS ABAP
                                                    
Affected system
                                                            type
                                                        
                                                            SAP Business One
                                                    
                                                
                                                        Patchday
2021-05
                                                    
                                                Released
                                                            on
2021/05/11
                                                    
                                                Description
                                                        [CVE-2021-27616] Multiple vulnerabilities in SAP Business One, version for SAP HANA (Business-One-Hana-Chef-Cookbook)
                                                    
Affected system
                                                            type
                                                        
                                                            SAP Business One
                                                    
                                                
                                                        Patchday
2021-05
                                                    
                                                Released
                                                            on
2021/05/11
                                                    
                                                Description
                                                        [CVE-2021-27613] Information Disclosure in SAP Business One (Chef business-one-cookbook)
                                                    
Affected system
                                                            type
                                                        
                                                            SAP Commerce Cloud
                                                    
                                                
                                                        Patchday
2021-05
                                                    
                                                Released
                                                            on
2021/05/11
                                                    
                                                Description
                                                        [CVE-2021-27619] Information Disclosure in SAP Commerce (Backoffice search)
                                                    
Affected system
                                                            type
                                                        
                                                            ABAP
                                                    
                                                
                                                        Patchday
2021-05
                                                    
                                                Released
                                                            on
2021/04/27
                                                    
                                                Description
                                                        Unauthorized use of application functions in SAP GUI for HTML
                                                    
Affected system
                                                            type
                                                        
                                                            Java
                                                    
                                                
                                                        Patchday
2021-05
                                                    
                                                Released
                                                            on
2021/05/11
                                                    
                                                Description
                                                        Information Disclosure in Enterprise Services Repository of SAP Process Integration
                                                    
Affected system
                                                            type
                                                        
                                                            Java
                                                    
                                                
                                                        Patchday
2021-05
                                                    
                                                Released
                                                            on
2021/05/11
                                                    
                                                Description
                                                        [Multiple CVEs] Multiple vulnerabilities in SAP Process Integration (Integration Builder Framework)
                                                    
Affected system
                                                            type
                                                        
                                                            SAP CRM UI
                                                    
                                                
                                                        Patchday
2021-05
                                                    
                                                Released
                                                            on
2021/04/27
                                                    
                                                Description
                                                        Cross-Site Request Forgery (CSRF) vulnerability in SAP CRM WebClient UI
                                                    
Affected system
                                                            type
                                                        
                                                            SAP GUI / Frontend
                                                    
                                                
                                                        Patchday
2021-05
                                                    
                                                Released
                                                            on
2021/05/11
                                                    
                                                Description
                                                        [CVE-2021-27612] SAP GUI for Windows is vulnerable to redirect users to an untrusted website