We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 18 and the highest CVSS score is 10.0.

 

Severity
SAP© Security advisories 18
 System Types
Affected SAP© system types

 

3305369
CVSS
10.0

Affected system type Java
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-27497] Multiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge and EventLogServiceCollector)
3298961
CVSS
9.8

Affected system type BI/BO platform
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-28765] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management )
3305907
CVSS
8.7

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29186] Directory Traversal vulnerability in SAP NetWeaver ( BI CONT ADD ON)
3312733
CVSS
6.8

Affected system type Java
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-26458] Information Disclosure vulnerability in SAP Landscape Management
3311624
CVSS
6.7

Affected system type SAP GUI / Frontend
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29187] DLL Hijacking vulnerability in SapSetup (Software Installation Program)
3289994
CVSS
6.5

Affected system type Java
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-28761] Missing Authentication check in SAP NetWeaver Enterprise Portal
3296378
CVSS
6.5

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-28763] - Denial of Service in SAP NetWeaver AS for ABAP and ABAP Platform
3275458
CVSS
6.1

Affected system type Kernel
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-27499] Cross-Site Scripting (XSS) vulnerability in SAP GUI for HTML
3309056
CVSS
6.0

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-27897] Code Injection vulnerability in SAP CRM
3269352
CVSS
5.4

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29189] HTTP Verb Tampering vulnerability in SAP CRM (WebClient UI)
3303060
CVSS
5.3

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29185] Denial of Service (DOS) in SAP NetWeaver AS for ABAP (Business Server Pages)
3315312
CVSS
5.0

Affected system type Kernel
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29108] IP filter vulnerability in ABAP Platform and SAP Web Dispatcher
3316509
CVSS
4.7

Affected system type SAP Commerce
Patchday 2023-04
Released on 2023/04/11
Description Remote Code Execution vulnerability in SAP Commerce
3115598
CVSS
4.4

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29109] Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard)
3301457
CVSS
4.3

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-1903] Missing Authorization check in SAP HCM Fiori App My Forms (Fiori 2.0)
3114489
CVSS
3.7

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29112] Code Injection vulnerability in SAP Application Interface Framework (Message Monitoring)
3113349
CVSS
3.7

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29110] Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard)
3117978
CVSS
3.1

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29111] Information Disclosure vulnerability in SAP Application Interface Framework (ODATA service)