We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

× Hey there! Glad you made it.
We have found 9 security advices for you to review.

 

Severity
SAP© Security advisories 9
 System Types
Affected SAP© system types

 

3046610
CVSS
8.2

Affected system type ABAP
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27611] Code Injection vulnerability in SAP NetWeaver AS ABAP
3049661
CVSS
7.8

Affected system type SAP Business One
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27616] Multiple vulnerabilities in SAP Business One, version for SAP HANA (Business-One-Hana-Chef-Cookbook)
3049755
CVSS
7.8

Affected system type SAP Business One
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27613] Information Disclosure in SAP Business One (Chef business-one-cookbook)
3039818
CVSS
6.5

Affected system type SAP Commerce Cloud
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27619] Information Disclosure in SAP Commerce (Backoffice search)
2114798
CVSS
6.3

Affected system type ABAP
Patchday 2021-05
Released on 2021/04/27
Description Unauthorized use of application functions in SAP GUI for HTML
2745860
CVSS
5.3

Affected system type Java
Patchday 2021-05
Released on 2021/05/11
Description Information Disclosure in Enterprise Services Repository of SAP Process Integration
3012021
CVSS
4.9

Affected system type Java
Patchday 2021-05
Released on 2021/05/11
Description [Multiple CVEs] Multiple vulnerabilities in SAP Process Integration (Integration Builder Framework)
2904569
CVSS
4.6

Affected system type SAP CRM UI
Patchday 2021-05
Released on 2021/04/27
Description Cross-Site Request Forgery (CSRF) vulnerability in SAP CRM WebClient UI
3023078
CVSS
3.4

Affected system type SAP GUI / Frontend
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27612] SAP GUI for Windows is vulnerable to redirect users to an untrusted website