We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 14 and the highest CVSS score is 10.0.

 

Severity
SAP© Security advisories 14
 System Types
Affected SAP© system types

 

3154684
CVSS
10.0

Affected system type SAP Work Manager
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Work Manager
3145987
CVSS
9.3

Affected system type SAP Solution Manager...
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24396] Missing Authentication check in SAP Focused Run (Simple Diagnostics Agent 1.0)
3149805
CVSS
8.1

Affected system type ABAP
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26101] Cross-Site Scripting (XSS) vulnerability in SAP Fiori launchpad
3146260
CVSS
6.1

Affected system type Java
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24397] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3146261
CVSS
6.1

Affected system type Java
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24395] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3147283
CVSS
5.4

Affected system type SAP Solution Manager...
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24399] Cross-Site Scripting (XSS) vulnerability in SAP Focused Run (Real User Monitoring)
3145997
CVSS
5.4

Affected system type ABAP
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26102] Missing authorization check in SAP NetWeaver Application Server for ABAP
3144941
CVSS
5.4

Affected system type SAP Financial Consolidation
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26104] Missing Authorization check in SAP Financial Consolidation
3147102
CVSS
5.3

Affected system type SAP Solution Manager...
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-22547] Information Disclosure vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)
1753378
CVSS
5.3

Affected system type Java
Patchday 2022-03
Released on 2013/08/13
Description Directory traversal in Web Container
3103424
CVSS
5.0

Affected system type BI/BO platform
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24398] Information Disclosure vulnerability in SAP Business Objects Business Intelligence Platform
3111110
CVSS
4.8

Affected system type SAPCAR
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26100] Denial of service (DOS) in SAPCAR
3132360
CVSS
3.7

Affected system type Java
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26103] Information Disclosure vulnerability in SAP NetWeaver(Real Time Messaging Framework)
3104349
CVSS
3.3

Affected system type ABAP
Patchday 2022-03
Released on 2022/03/22
Description Missing authorization check in S/4HANA finance for advanced payment management