We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

× Hey there! Glad you made it.
We have found 10 security advices for you to review.

 

Severity
SAP© Security advisories 10
 System Types
Affected SAP© system types

 

3223392
CVSS
7.8

Affected system type SAP Business One
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-35292] Windows Unquoted Service Path issue in SAP Business One
3217303
CVSS
7.7

Affected system type BI/BO platform
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-39014] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (CMC)
3237075
CVSS
7.1

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-39801] Insufficient Firefighter Session Expiration in SAP GRC Access Control Emergency Access Management
3159736
CVSS
6.7

Affected system type SAP Host Agent
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-35295] Privilege Escalation Vulnerability in SAPOSCOL on Unix
2634023
CVSS
6.3

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description Missing authorization check in Consumption of CDS Views (or) OData Services in QM-QN
3229820
CVSS
6.1

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-39799] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad)
3219164
CVSS
6.1

Affected system type Java
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-35298] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC)
3218177
CVSS
5.4

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-35294] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
3198137
CVSS
4.7

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description Update 1 to Security Note 3165333 - [CVE-2022-28215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform
3126968
CVSS
4.3

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description Information Disclosure vulnerability in SAP CRM WebClient