We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 181 and the highest CVSS score is 10.0.

 

Severity
SAP© Security advisories 181
 System Types
Affected SAP© system types

 

3273480
CVSS
9.9

Affected system type Java
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41272] Improper access control in SAP NetWeaver AS Java (User Defined Search)
3239475
CVSS
9.9

Affected system type BI/BO platform
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41267] Server-Side Request Forgery vulnerability in SAP BusinessObjects Business Intelligence Platform
3271523
CVSS
9.8

Affected system type SAP Commerce
Patchday 2022-12
Released on 2022/12/13
Description Remote Code Execution vulnerability associated with Apache Commons Text in SAP Commerce
3267780
CVSS
9.4

Affected system type Java
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41271] Improper access control in SAP NetWeaver AS Java (Messaging System)
3268172
CVSS
8.8

Affected system type ABAP
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41264] Code Injection vulnerability in SAP BASIS
3271091
CVSS
8.5

Affected system type ABAP
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41268] Privilege escalation vulnerability in SAP Business Planning and Consolidation
3248255
CVSS
8.0

Affected system type SAP Commerce
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41266] Cross-Site Scripting (XSS) vulnerability in SAP Commerce
3266846
CVSS
6.5

Affected system type SAP Disclosure Management
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41274] Missing Authorization Checks in SAP Disclosure Management
3271313
CVSS
6.1

Affected system type ABAP
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41275] Offener Redirect in SAP Solutions Manager (Enterprise Search)
3258950
CVSS
6.1

Affected system type ABAP
Patchday 2022-12
Released on 2022/12/13
Description Update 1 to Security Note 2872782 - [CVE-2020-6215] URL Redirection vulnerability in SAP NetWeaver AS ABAP (BSP Test Application)
3262544
CVSS
6.1

Affected system type Java
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41262] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for Java (Http Provider Service)
3265173
CVSS
6.0

Affected system type Java
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41261] Improper Access Control in SAP Solution Manager (Diagnostic Agent)
3249648
CVSS
4.3

Affected system type BI/BO platform
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41263] Missing authentication check vulnerability in SAP Business Objects Business Intelligence Platform (Web intelligence)
3270399
CVSS
4.3

Affected system type Java
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41273] URL Redirection vulnerability in SAP Sourcing and SAP Contract Lifecycle Management
3243924
CVSS
9.9

Affected system type BI/BO platform
Exploit available
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41203] Insecure Deserialization of Untrusted Data in SAP BusinessObjects Business Intelligence Platform (Central Management Console and BI Launchpad)
3256571
CVSS
8.7

Affected system type ABAP
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41214] Multiple vulnerabilities in SAP NetWeaver Application Server ABAP and ABAP Platform
3249990
CVSS
7.5

Affected system type SAP UI5
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2021-20223] Multiple Vulnerabilities in SQlite bundled with SAPUI5
3263436
CVSS
7.0

Affected system type SAP 3D Visual Enterprise
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41211] Arbitrary Code Execution vulnerability in SAP 3D Visual Enterprise Author and SAP 3D Visual Enterprise Viewer
3260708
CVSS
6.5

Affected system type SAP Financial Consolidation
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41258] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation
3229987
CVSS
6.5

Affected system type Sybase platform
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41259] Denial of service (DOS) in SAP SQL Anywhere
3218159
CVSS
6.1

Affected system type SAP UI5 SAP Fiori
Patchday 2022-11
Released on 2022/11/08
Description Insufficient Session Expiration in Central Fiori Launchpad
3238042
CVSS
6.1

Affected system type Java
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41207] URL Redirection vulnerability in SAP Biller Direct
3237251
CVSS
5.5

Affected system type SAP GUI / Frontend
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41205] Code injection vulnerability in SAP GUI for Windows
3251202
CVSS
4.7

Affected system type ABAP
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform
3242933
CVSS
9.9

Affected system type Java
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-39802] File path traversal vulnerability in SAP Manufacturing Execution
3229132
CVSS
8.2

Affected system type BI/BO platform
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-39013] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Program Objects)
3232021
CVSS
8.1

Affected system type Sybase platform
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-35299] Buffer Overflow in SAP SQL Anywhere and SAP IQ
3239293
CVSS
7.7

Affected system type BI/BO platform
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-39015] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform(AdminTools/ Query Builder)
3245928
CVSS
7.0

Affected system type SAP 3D Visual Enterprise
Patchday 2022-10
Released on 2022/10/11
Description [Multiple CVEs] Multiple vulnerabilities in SAP 3D Visual Enterprise Viewer
3245929
CVSS
7.0

Affected system type SAP 3D Visual Enterprise
Patchday 2022-10
Released on 2022/10/11
Description [Multiple CVEs] Multiple vulnerabilities in SAP 3D Visual Enterprise Author
3233226
CVSS
6.8

Affected system type BI/BO platform
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-35296] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Version Management System)
3049899
CVSS
6.5

Affected system type SAP Enable Now
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-35297] Stored Cross-Site Scripting (XSS) vulnerability in SAP Enable Now
2495712
CVSS
6.5

Affected system type ABAP
Patchday 2022-10
Released on 2022/10/11
Description Missing authorization check in SAP Automotive Solutions
3202523
CVSS
6.1

Affected system type SAP Commerce
Patchday 2022-10
Released on 2022/10/11
Description Cross-Site Scripting (XSS) vulnerability in SAP Commerce
3211161
CVSS
6.1

Affected system type BI/BO platform
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-39800] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI LaunchPad)
3229425
CVSS
5.4

Affected system type BI/BO platform
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-41206] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform / Analysis for OLAP
3248970
CVSS
4.9

Affected system type SAP Customer Data Cloud
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-41209] Information Disclosure Vulnerability in SAP Customer Data Cloud (Gigya)
3248384
CVSS
4.9

Affected system type SAP Customer Data Cloud
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-41210] Information Disclosure Vulnerability in SAP Customer Data Cloud (Gigya)
3167342
CVSS
4.8

Affected system type BI/BO platform
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-35226] Cross-Site Scripting (XSS) vulnerability in Data Services Management Console
3234755
CVSS
4.3

Affected system type ABAP
Patchday 2022-10
Released on 2022/10/11
Description Information Disclosure vulnerability in Master Data Governance
3223392
CVSS
7.8

Affected system type SAP Business One
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-35292] Windows Unquoted Service Path issue in SAP Business One
3217303
CVSS
7.7

Affected system type BI/BO platform
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-39014] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (CMC)
3237075
CVSS
7.1

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-39801] Insufficient Firefighter Session Expiration in SAP GRC Access Control Emergency Access Management
3159736
CVSS
6.7

Affected system type SAP Host Agent
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-35295] Privilege Escalation Vulnerability in SAPOSCOL on Unix
2634023
CVSS
6.3

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description Missing authorization check in Consumption of CDS Views (or) OData Services in QM-QN
3219164
CVSS
6.1

Affected system type Java
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-35298] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC)
3229820
CVSS
6.1

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-39799] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad)
3218177
CVSS
5.4

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-35294] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
3198137
CVSS
4.7

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description Update 1 to Security Note 3165333 - [CVE-2022-28215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform
3126968
CVSS
4.3

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description Information Disclosure vulnerability in SAP CRM WebClient
3210823
CVSS
8.2

Affected system type BI/BO platform
Patchday 2022-08
Released on 2022/08/09
Description [CVE-2022-32245] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Open Document)
3213141
CVSS
7.3

Affected system type SAP Landscape...
Patchday 2022-08
Released on 2022/07/26
Description Information Disclosure in SAP Landscape Management
3156484
CVSS
6.5

Affected system type SAP GUI / Frontend
Patchday 2022-08
Released on 2022/08/09
Description Information Disclosure vulnerability in SAP Business Client
2522794
CVSS
6.3

Affected system type ABAP
Patchday 2022-08
Released on 2022/08/09
Description Missing Authorization check in Portugal Digital Signature
3216653
CVSS
5.3

Affected system type SAP Authenticator for Android
Patchday 2022-08
Released on 2022/08/09
Description [CVE-2022-35290] Information Disclosure in SAP Authenticator for Android
3213524
CVSS
5.2

Affected system type BI/BO platform
Patchday 2022-08
Released on 2022/08/09
Description [CVE-2022-32244] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Commentary DB)
3213507
CVSS
5.2

Affected system type BI/BO platform
Patchday 2022-08
Released on 2022/08/09
Description [CVE-2022-31596] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Monitoring DB)
3210566
CVSS
4.2

Affected system type SAP Enable Now
Patchday 2022-08
Released on 2022/08/09
Description [CVE-2022-35293] Missing authorization check in SAP Enable Now Manager
3221288
CVSS
8.3

Affected system type BI/BO platform
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35228] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)
3212997
CVSS
7.6

Affected system type SAP Business One
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-32249] Information Disclosure vulnerability in SAP Business One
3157613
CVSS
7.5

Affected system type SAP Business One
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-28771] Missing Authentication check in SAP Business One (License service API)
3191012
CVSS
7.4

Affected system type SAP Business One
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-31593] Code Injection vulnerability in SAP Business One
3169239
CVSS
6.5

Affected system type BI/BO platform
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-29619] Information Disclosure to user Administrator in SAP BusinessObjects Business Intelligence Platform 4.x
2726124
CVSS
6.3

Affected system type ABAP
Patchday 2022-07
Released on 2022/06/28
Description Missing Authorization Check in multiple components under SAP Automotive Solutions
3209557
CVSS
6.1

Affected system type Java
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-32247] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3210779
CVSS
6.1

Affected system type Java
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35224] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Portal
3208880
CVSS
6.1

Affected system type Java
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35225] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3207902
CVSS
6.1

Affected system type Java
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35172] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3211760
CVSS
6.1

Affected system type Java
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35227] Cross-Site Scripting (XSS) vulnerability in SAP NW EP WPC
3208819
CVSS
6.1

Affected system type Java
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35170] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3194361
CVSS
6.0

Affected system type BI/BO platform
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35169] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (LCM)
3167430
CVSS
5.6

Affected system type BI/BO platform
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-31591] Privilege Escalation vulnerability in SAP BusinessObjects (BW Publisher Service)
3213279
CVSS
5.4

Affected system type BI/BO platform
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-31598] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects
3203079
CVSS
5.4

Affected system type BI/BO platform
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-32246] SQL Injection vulnerability in SAP BusinessObjects Business Intelligence Platform (Visual Difference Application)
3213826
CVSS
5.4

Affected system type ABAP
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-31597] Missing Authorization check in SAP S/4HANA(business partner extension for Spain/Slovakia)
3150454
CVSS
4.9

Affected system type ABAP
Patchday 2022-07
Released on 2022/07/12
Description Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
3150463
CVSS
4.9

Affected system type ABAP
Patchday 2022-07
Released on 2022/07/12
Description Information Disclosure vulnerability in ABAP Platform
3216161
CVSS
4.3

Affected system type ABAP
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-32248] Missing Input Validation in Manage Checkbooks component of SAP S/4HANA
3196280
CVSS
4.3

Affected system type ABAP
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-31592] Missing Authorization check in EA-DFPS
3211203
CVSS
4.3

Affected system type SAP Business One
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35168] Denial of Service vulnerability in SAP Business One
3220746
CVSS
3.3

Affected system type SAP 3D Visual Enterprise
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35171] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3158375
CVSS
8.6

Affected system type SAProuter
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-27668] Improper Access Control of SAProuter for SAP NetWeaver and ABAP Platform
3147498
CVSS
8.2

Affected system type Java
Patchday 2022-06
Released on 2022/06/14
Description Improper Access Control check in SAP NetWeaver basicadmin and adminadapter services
3197005
CVSS
7.8

Affected system type SAP PowerDesigner
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-31590] Potential privilege escalation in SAP PowerDesigner Proxy 16.7
3206271
CVSS
6.5

Affected system type SAP 3D Visual Enterprise
Patchday 2022-06
Released on 2022/06/14
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3134161
CVSS
6.5

Affected system type ABAP
Patchday 2022-06
Released on 2022/06/14
Description Missing Authorization check in SAP ERP HCM
3197927
CVSS
6.1

Affected system type SAP...
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-29618] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Development Infrastructure (Design Time Repository)
3203065
CVSS
5.0

Affected system type ABAP
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-31589] Segregation of Duty vulnerability in IL FI-AP File from SHAAM program.
3158815
CVSS
5.0

Affected system type SAP Financial Consolidation
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-31595] Privilege escalation vulnerability in SAP Financial Consolidation
3194674
CVSS
5.0

Affected system type ABAP SAP Host Agent
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-29612] Server-Side Request Forgery in SAP NetWeaver, ABAP Platform and SAP Host Agent
3158619
CVSS
4.9

Affected system type ABAP Java HANA platform
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-29614] Privilege Escalation in SAP startservice of SAP NetWeaver AS ABAP, AS Java, ABAP Platform and HANA Database
3191812
CVSS
3.7

Affected system type UI5
Patchday 2022-06
Released on 2022/06/14
Description Cross-Site Scripting (XSS) vulnerability in SAP Marketing Campaigns App
3190675
CVSS
3.7

Affected system type UI5
Patchday 2022-06
Released on 2022/06/14
Description Unsafe use of target blank in SAP Marketing Campaigns
3202846
CVSS
3.4

Affected system type Java
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-29615] Multiple vulnerabilities associated with Apache log4j 1.x component in SAP NetWeaver Developer Studio (NWDS)
3155571
CVSS
3.2

Affected system type SAP Adaptive Server...
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-31594] Privilege escalation vulnerability in SAP Adaptive Server Enterprise (ASE)
3189409
CVSS
9.8

Affected system type SAP Business One Cloud
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in in SAP Business One Cloud
3145046
CVSS
8.3

Affected system type Kernel
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-27656] Cross-Site Scripting (XSS) vulnerability in administration UI of SAP Webdispatcher and SAP Netweaver AS for ABAP and Java (ICM)
2998510
CVSS
7.8

Affected system type BI/BO platform
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-28214] Central Management Server Information Disclosure in Business Intelligence Update
3165801
CVSS
6.5

Affected system type ABAP
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-29611] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
3164677
CVSS
6.5

Affected system type ABAP
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-29613] Information Disclosure vulnerability in SAP Employee Self Service(Fiori My Leave Request)
2754555
CVSS
6.3

Affected system type ABAP
Patchday 2022-05
Released on 2022/05/10
Description Cross-Site Request Forgery (CSRF) vulnerability in F0673 Approve Bank Payments back-end
2756188
CVSS
6.3

Affected system type UI5
Patchday 2022-05
Released on 2022/05/10
Description Cross-Site Request Forgery (CSRF) vulnerability in F0673 Approve Bank Payments front-end
3146336
CVSS
5.4

Affected system type ABAP
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-29610] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
3145702
CVSS
5.3

Affected system type SAP Host Agent Kernel
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-29616] Memory Corruption vulnerability in SAP Host Agent, SAP NetWeaver and ABAP Platform
3158188
CVSS
5.3

Affected system type SAP Host Agent
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-28774] Information Disclosure vulnerability in SAP Host Agent logfile
3143161
CVSS
4.3

Affected system type ABAP
Patchday 2022-05
Released on 2022/05/10
Description Missing Authorization check for UI5 flexibility key user functionality
3189635
CVSS
9.8

Affected system type SAP Customer...
Patchday 2022-04
Released on 2022/04/14
Description [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Profitability Analytics
3187290
CVSS
9.8

Affected system type SAP Customer Checkout
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Checkout
3170990
CVSS
9.8

Affected system type Any
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-22965] Central Security Note for Remote Code Execution vulnerability associated with Spring Framework
3189428
CVSS
9.8

Affected system type SAP HANA Platform
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP HANA Extended Application Services
3189429
CVSS
9.8

Affected system type Java
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in PowerDesigner Web (up to including 16.7 SP05 PL01)
3171258
CVSS
9.8

Affected system type SAP Commerce
Patchday 2022-04
Released on 2022/04/18
Description [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Commerce
3158613
CVSS
9.1

Affected system type Java
Patchday 2022-04
Released on 2022/04/12
Description Update 1 to Security Note 3022622 - [CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence
3130497
CVSS
8.2

Affected system type BI/BO platform
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-27671] CSRF token visible in one of the URL in SAP Business Intelligence Platform.
3111311
CVSS
7.5

Affected system type Kernel
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-28772]Denial of service (DOS) in SAP Web Dispatcher and SAP Netweaver (Internet Communication Manager)
3155609
CVSS
7.0

Affected system type SAP Commerce
Patchday 2022-04
Released on 2022/04/12
Description Privilege escalation vulnerability in Apache Tomcat server component of SAP Commerce
3137191
CVSS
6.8

Affected system type BI/BO platform
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-22541] Information Disclosure vulnerability in SAP BusinessObjects Platform
3148377
CVSS
6.5

Affected system type Java
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-28217] Missing XML Validation vulnerability in SAP NW EP WPC
3143437
CVSS
6.5

Affected system type SAP 3D Visual Enterprise
Patchday 2022-04
Released on 2022/04/12
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3148094
CVSS
6.5

Affected system type Sybase
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-27670] Denial of service (DOS) in SQL Anywhere
3126557
CVSS
6.1

Affected system type ABAP
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-28770] Cross-Site Scripting (XSS) vulnerability in SAPUI5 (vbm library)
3163703
CVSS
6.1

Affected system type ABAP
Patchday 2022-04
Released on 2022/04/12
Description Multiple Vulnerabilities in URI.js bundled with SAPUI5
3163583
CVSS
6.1

Affected system type Java
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-26105] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3132633
CVSS
5.4

Affected system type SAP GUI / Frontend
Patchday 2022-04
Released on 2022/04/12
Description Information Disclosure vulnerability in SAP GUI for Windows
3055044
CVSS
5.4

Affected system type BI/BO platform
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-28213] Missing XML Validation vulnerability in SAP BusinessObjects Business Intelligence Platform (dswsbobje - SOAP Web services)
3152442
CVSS
5.3

Affected system type Java
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-27669] Missing Authentication check in XML Data Archiving Service
3145769
CVSS
5.3

Affected system type BI/BO platform
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-27667] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (CMC)
3111293
CVSS
4.9

Affected system type Kernel
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-28773] Denial of service (DOS) in SAP Web Dispatcher and SAP Netweaver (Internet Communication Manager)
3165333
CVSS
4.7

Affected system type ABAP
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-28215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform
3165856
CVSS
4.3

Affected system type SAP Innovation Management
Patchday 2022-04
Released on 2022/03/28
Description [CVE-2022-27658] Missing authorization check in SAP Innovation Management
3150845
CVSS
4.3

Affected system type BI/BO platform
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-28216] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI Workspace)
3138299
CVSS
4.1

Affected system type Adobe LiveCycle Designer
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2021-44832] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP NetWeaver ABAP Server and ABAP Platform (Adobe LiveCycle Designer 11.0)
3101986
CVSS
4.1

Affected system type ABAP
Patchday 2022-04
Released on 2022/04/12
Description Prepare CSP support for On-Premise down port for code dependency in SAP CRM WebClient UI
3159091
CVSS
2.7

Affected system type SAP Solution Manager...
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-27657] Directory Traversal vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)
3154684
CVSS
10.0

Affected system type SAP Work Manager
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Work Manager
3145987
CVSS
9.3

Affected system type SAP Solution Manager...
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24396] Missing Authentication check in SAP Focused Run (Simple Diagnostics Agent 1.0)
3149805
CVSS
8.1

Affected system type ABAP
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26101] Cross-Site Scripting (XSS) vulnerability in SAP Fiori launchpad
3146260
CVSS
6.1

Affected system type Java
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24397] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3146261
CVSS
6.1

Affected system type Java
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24395] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3147283
CVSS
5.4

Affected system type SAP Solution Manager...
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24399] Cross-Site Scripting (XSS) vulnerability in SAP Focused Run (Real User Monitoring)
3145997
CVSS
5.4

Affected system type ABAP
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26102] Missing authorization check in SAP NetWeaver Application Server for ABAP
3144941
CVSS
5.4

Affected system type SAP Financial Consolidation
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26104] Missing Authorization check in SAP Financial Consolidation
3147102
CVSS
5.3

Affected system type SAP Solution Manager...
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-22547] Information Disclosure vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)
1753378
CVSS
5.3

Affected system type Java
Patchday 2022-03
Released on 2013/08/13
Description Directory traversal in Web Container
3103424
CVSS
5.0

Affected system type BI/BO platform
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24398] Information Disclosure vulnerability in SAP Business Objects Business Intelligence Platform
3111110
CVSS
4.8

Affected system type SAPCAR
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26100] Denial of service (DOS) in SAPCAR
3132360
CVSS
3.7

Affected system type Java
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26103] Information Disclosure vulnerability in SAP NetWeaver(Real Time Messaging Framework)
3104349
CVSS
3.3

Affected system type ABAP
Patchday 2022-03
Released on 2022/03/22
Description Missing authorization check in S/4HANA finance for advanced payment management
3139893
CVSS
10.0

Affected system type None
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Dynamic Authorization Management
3142773
CVSS
10.0

Affected system type SAP Commerce
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Commerce
3123396
CVSS
10.0

Affected system type Kernel
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22536] Request smuggling and request concatenation in SAP NetWeaver, SAP Content Server and SAP Web Dispatcher
3130920
CVSS
10.0

Affected system type SAP Data Intelligence
Patchday 2022-02
Released on 2022/01/18
Description Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Data Intelligence 3 (on-premise)
3140940
CVSS
9.1

Affected system type Java
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22544] Missing segregation of duties in SAP Solution Manager Diagnostics Root Cause Analysis Tools
3123427
CVSS
8.1

Affected system type Kernel
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22532] HTTP Request Smuggling in SAP NetWeaver Application Server Java
3140587
CVSS
7.1

Affected system type ABAP
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22540] SQL Injection vulnerability in SAP NetWeaver AS ABAP (Workplace Server)
3142092
CVSS
6.5

Affected system type ABAP
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22542] Information Disclosure vulnerability in SAP S/4HANA (Supplier Factsheet and Enterprise Search for Business Partner, Supplier and Customer)
3126489
CVSS
6.5

Affected system type ABAP
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22535] Missing Authorization check in SAP ERP HCM
2531036
CVSS
6.3

Affected system type ABAP
Patchday 2022-02
Released on 2019/04/09
Description Switchable Authorization checks for RFC BCA_DIM_RESET_TRIGGER_TABLE in Loans (FI-CAX-FS)
3140564
CVSS
5.6

Affected system type SAP Adaptive Server...
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22528] Information Disclosure in SAP Adaptive Server Enterprise
3126748
CVSS
5.4

Affected system type BI/BO platform
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22546] XSS vulnerability in SAP Business Objects Web Intelligence (BI Launchpad)
3128473
CVSS
4.9

Affected system type ABAP
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22545] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
3124994
CVSS
4.7

Affected system type ABAP
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22534] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver
3134684
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2022-02
Released on 2022/02/08
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3107196
CVSS
4.3

Affected system type ABAP
Patchday 2022-02
Released on 2022/01/25
Description Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver AS ABAP within Web Dynpro ABAP
3116223
CVSS
3.7

Affected system type Kernel
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22543] Denial of service (DOS) in SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel)
3132058
CVSS
10.0

Affected system type SAP IoT
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Cloud-to-Cloud Interoperability
3136988
CVSS
10.0

Affected system type SAP IoT
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Reference Template for enabling ingestion and persistence of time series data in Azure
3132515
CVSS
10.0

Affected system type SAP Edge Services 
Patchday 2022-01
Released on 2021/12/30
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services Cloud Edition
3132177
CVSS
10.0

Affected system type SAP Localization Hub
Patchday 2022-01
Released on 2021/12/22
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Localization Hub, digital compliance service for India
3134139
CVSS
10.0

Affected system type SAP Enterprise...
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j2 component used in SAP Enterprise Continuous Testing by Tricentis
3136094
CVSS
10.0

Affected system type SAP Digital...
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Digital Manufacturing Cloud for Edge Computing
3131740
CVSS
9.8

Affected system type SAP Business One
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Business One
3112928
CVSS
8.7

Affected system type ABAP
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2022-22531] Multiple vulnerabilities in F0743 Create Single Payment application of SAP S/4HANA
3134531
CVSS
7.5

Affected system type SAP HANA Platform
Patchday 2022-01
Released on 2021/12/24
Description [CVE-2021-44228] Denial of Service vulnerability associated with Apache Log4j component used in XSA Cockpit
3135581
CVSS
6.6

Affected system type Java
Patchday 2022-01
Released on 2022/01/11
Description Update 3 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration
3101299
CVSS
6.6

Affected system type SAP Business One
Patchday 2022-01
Released on 2021/12/14
Description [CVE-2021-42066] Information Disclosure vulnerability in SAP Business One
3106528
CVSS
6.5

Affected system type SAP Business One
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2021-44234] Information Disclosure vulnerability in SAP Business One
3124597
CVSS
6.1

Affected system type SAP Enterprise Threat...
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2022-22529] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Threat Detection
3131691
CVSS
5.5

Affected system type Adobe LiveCycle Designer
Patchday 2022-01
Released on 2021/12/30
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP NetWeaver ABAP Server and ABAP Platform (Adobe LiveCycle Designer 11.0)
3133005
CVSS
5.3

Affected system type Java
Patchday 2022-01
Released on 2021/12/28
Description Update 2 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration
3112710
CVSS
4.3

Affected system type ABAP
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2021-42067] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform