We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 136 and the highest CVSS score is 9.8.

 

Severity
SAP© Security advisories 136
 System Types
Affected SAP© system types

 

3536965
CVSS
9.1

Affected system type Java
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-47578] Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)
3520281
CVSS
8.8

Affected system type SAP Web Dispatcher
Patchday 2024-12
Released on 2024/11/12
Description [CVE-2024-47590] Cross-Site Scripting (XSS) vulnerability in SAP Web Dispatcher
3469791
CVSS
8.5

Affected system type ABAP
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-54198] Information Disclosure vulnerability through Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP
3504390
CVSS
7.5

Affected system type ABAP
Patchday 2024-12
Released on 2024/11/12
Description [CVE-2024-47586] NULL Pointer Dereference vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
3542543
CVSS
7.2

Affected system type Java
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-54197] Server-Side Request Forgery in SAP NetWeaver Administrator (System Overview)
3524933
CVSS
5.3

Affected system type BI/BO platform
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-32732] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform
3351041
CVSS
5.3

Affected system type Java
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-47582] XML Entity Expansion Vulnerability in SAP NetWeaver AS JAVA
3515653
CVSS
4.3

Affected system type BI/BO platform
Patchday 2024-12
Released on 2024/12/10
Description Update 1 to Security Note 3433545: [CVE-2024-42375] Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform
3536361
CVSS
4.3

Affected system type ABAP
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-47585] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
3433545
CVSS
4.3

Affected system type BI/BO platform
Patchday 2024-12
Released on 2024/08/13
Description [CVE-2024-42375] Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform
3522332
CVSS
4.2

Affected system type ABAP
Patchday 2024-12
Released on 2024/11/26
Description [CVE-2024-47581] Missing Authorization check in SAP HCM (Approve Timesheets version 4)
3504847
CVSS
3.3

Affected system type SAP Product Lifecycle Costing
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-47576] DLL Hijacking vulnerability in SAP Product Lifecycle Costing
3535451
CVSS
2.7

Affected system type SAP Commerce Cloud
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-47577] Information Disclosure vulnerability in SAP Commerce Cloud
3335394
CVSS
6.5

Affected system type Java
Patchday 2024-11
Released on 2024/11/12
Description [CVE-2024-42372] Missing Authorization check in SAP NetWeaver AS Java (System Landscape Directory)
3509619
CVSS
6.3

Affected system type SAP Host Agent
Patchday 2024-11
Released on 2024/11/12
Description [CVE-2024-47595] Local Privilege Escalation in SAP Host Agent
3393899
CVSS
5.3

Affected system type Java
Patchday 2024-11
Released on 2024/11/12
Description [CVE-2024-47592] Information Disclosure Vulnerability in SAP NetWeaver Application Server Java (Logon Application)
3522953
CVSS
4.7

Affected system type Java
Patchday 2024-11
Released on 2024/11/12
Description [CVE-2024-47588] Information Disclosure vulnerability in SAP NetWeaver Java (Software Update Manager)
3508947
CVSS
4.3

Affected system type ABAP
Patchday 2024-11
Released on 2024/11/12
Description [CVE-2024-47593] Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
3498470
CVSS
3.5

Affected system type ABAP
Patchday 2024-11
Released on 2024/11/12
Description [CVE-2024-47587] Missing authorization check in SAP Cash Management (Cash Operations)
3392049
CVSS
3.5

Affected system type ABAP
Patchday 2024-11
Released on 2024/05/14
Description [CVE-2024-33000] Missing Authorization check in SAP Bank Account Management
3479478
CVSS
9.8

Affected system type BI/BO platform
Patchday 2024-10
Released on 2024/08/13
Description [CVE-2024-41730] Missing Authentication check in SAP BusinessObjects Business Intelligence Platform
3523541
CVSS
8.0

Affected system type SAP Enterprise...
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2022-23302] Multiple vulnerabilities in SAP Enterprise Project Connection
3478615
CVSS
7.7

Affected system type BI/BO platform
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2024-37179] Insecure File Operations vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)
3495876
CVSS
6.5

Affected system type Sybase platform
Patchday 2024-10
Released on 2024/08/13
Description [Multiple CVEs] Multiple vulnerabilities in SAP Replication Server (FOSS)
3477359
CVSS
6.0

Affected system type Java
Patchday 2024-10
Released on 2024/09/10
Description [CVE-2024-45283] Information disclosure vulnerability in SAP NetWeaver AS for Java (Destination Service)
3503462
CVSS
5.4

Affected system type Java
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2024-47594] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC)
3507545
CVSS
5.4

Affected system type SAP Commerce / SAP...
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2024-45278] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice
3481588
CVSS
4.3

Affected system type ABAP
Patchday 2024-10
Released on 2024/09/10
Description [CVE-2024-41729] Information Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer)
3520100
CVSS
4.3

Affected system type SAP HANA Client
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2024-45277] Prototype Pollution vulnerability in SAP HANA Client
3251893
CVSS
4.3

Affected system type ABAP
Patchday 2024-10
Released on 2024/09/24
Description [CVE-2024-45282] HTTP Verb Tampering in SAP S/4 HANA(Manage Bank Statements)
3479293
CVSS
4.3

Affected system type ABAP
Patchday 2024-10
Released on 2024/08/13
Description [CVE-2024-42373] Missing Authorization Check in SAP Student Life Cycle Management (SLcM)
3454858
CVSS
4.1

Affected system type ABAP
Patchday 2024-10
Released on 2024/07/09
Description [CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
3459935
CVSS
7.4

Affected system type SAP Commerce Cloud
Patchday 2024-09
Released on 2024/08/13
Description [CVE-2024-33003] Information Disclosure Vulnerability in SAP Commerce Cloud
3488341
CVSS
6.5

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-45286] Missing Authorization check in SAP Production and Revenue Accounting (Tobin interface)
3501359
CVSS
6.1

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-45279] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP(CRM Blueprint Application Builder Panel)
3497347
CVSS
6.1

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-42378] Cross-Site Scripting (XSS) in eProcurement on S/4HANA
3430336
CVSS
5.9

Affected system type SAP Commerce Cloud
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2013-3587] Information Disclosure vulnerability in SAP Commerce Cloud
3425287
CVSS
5.8

Affected system type BI/BO platform
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-45281] DLL hijacking vulnerability in SAP BusinessObjects Business Intelligence Platform
3488039
CVSS
5.4

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [Multiple CVEs] Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform
3505503
CVSS
4.8

Affected system type Java
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-45280] Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver AS Java (Logon Application)
3498221
CVSS
4.7

Affected system type Java
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-44120] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3505293
CVSS
4.3

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-44112] Missing Authorization check in SAP for Oil & Gas (Transportation and Distribution)
3437585
CVSS
4.3

Affected system type ABAP
Patchday 2024-09
Released on 2024/08/27
Description [CVE-2024-44121] Information Disclosure in SAP S/4 HANA (Statutory Reports)
3481992
CVSS
4.3

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-44113] Information Disclosure vulnerability in the SAP Business Warehouse (BEx Analyzer)
3496410
CVSS
2.7

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-41728] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
2256627
CVSS
2.7

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-45284] Missing authorization check in SAP Student Life Cycle Management (SLcM)
3507252
CVSS
2.0

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-44114] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
3477196
CVSS
9.1

Affected system type SAP Build Apps
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-29415] Server-Side Request Forgery vulnerability in applications built with SAP Build Apps
3485284
CVSS
8.2

Affected system type Java
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-42374] XML injection in SAP BEx Web Java Runtime Export Web Service
3423268
CVSS
7.8

Affected system type SAP Fiori
Patchday 2024-08
Released on 2024/07/23
Description [CVE-2023-30533] Prototype Pollution in SAP S/4 HANA (Manage Supply Protection)
3474590
CVSS
6.5

Affected system type ABAP
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-42376] Multiple Missing Authorization Check vulnerabilities in SAP Shared Service Framework
3438085
CVSS
6.3

Affected system type Kernel / Web Dispatcher
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-33005] Missing Authorization check in SAP NetWeaver Application Server (ABAP and Java),SAP Web Dispatcher and SAP Content Server.
3483256
CVSS
5.4

Affected system type SAP Commerce
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-41735] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice
3471450
CVSS
5.3

Affected system type SAP Commerce
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-41733] Information Disclosure Vulnerability in SAP Commerce
3487537
CVSS
5.0

Affected system type ABAP
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-41737] Server-Side Request Forgery (SSRF) in SAP CRM ABAP (Insights Management)
3468102
CVSS
4.7

Affected system type ABAP
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-41732] Improper Access Control in SAP Netweaver Application Server ABAP
3494349
CVSS
4.3

Affected system type ABAP
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-41734] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
3477423
CVSS
4.3

Affected system type ABAP
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-39591] Missing Authorization check in SAP Document Builder
3490515
CVSS
7.2

Affected system type SAP Commerce
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-39597] Improper Authorization Checks on Early Login Composable Storefront B2B sites of SAP Commerce
3466801
CVSS
6.9

Affected system type SAP Landscape...
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-39593] Information Disclosure vulnerability in SAP Landscape Management
3467377
CVSS
6.1

Affected system type SAP CRM UI
Patchday 2024-07
Released on 2024/07/09
Description [Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI)
3468681
CVSS
6.1

Affected system type Java
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-34685] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Knowledge Management XMLEditor
3482217
CVSS
6.1

Affected system type ABAP
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-39594] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Business Warehouse - Business Planning and Simulation
3457354
CVSS
5.4

Affected system type ABAP
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-37172] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)
3458789
CVSS
5.0

Affected system type ABAP
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-34689] Server-Side Request Forgery in SAP Business Workflow (WebFlow Services)
3469958
CVSS
5.0

Affected system type ABAP
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-37171] Server-Side Request Forgery (SSRF) in SAP Transportation Management (Collaboration Portal)
3483993
CVSS
5.0

Affected system type ABAP
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-34689] Prerequisite for Security Note 3458789
3461110
CVSS
5.0

Affected system type SAP GUI / Frontend
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-39600] Information Disclosure vulnerability in SAP GUI for Windows
3485805
CVSS
5.0

Affected system type ABAP
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-34689] Allowlisting of callback-URLs in SAP Business Workflow (WebFlow Services)
3456952
CVSS
4.7

Affected system type ABAP
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-39599] Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform
3476348
CVSS
4.3

Affected system type SAP Enable Now
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-39596] Missing Authorization check vulnerability in SAP Enable Now
3476340
CVSS
3.3

Affected system type SAP Enable Now
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-34692] Unrestricted File upload vulnerability in SAP Enable Now
3457592
CVSS
8.1

Affected system type SAP Financial Consolidation
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-37177] Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation
3460407
CVSS
7.5

Affected system type Java
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-34688] Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)
3466175
CVSS
6.5

Affected system type ABAP
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-34691] Missing Authorization check in SAP S/4HANA (Manage Incoming Payment Files)
3453170
CVSS
6.5

Affected system type ABAP
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-33001] Denial of service (DOS) in SAP NetWeaver and ABAP platform
3459379
CVSS
6.5

Affected system type ABAP
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-34683] Unrestricted file upload in SAP Document Builder (HTTP service)
3465129
CVSS
6.1

Affected system type ABAP
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-34686] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
3465455
CVSS
5.5

Affected system type ABAP
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-37176] Missing Authorization check in SAP BW/4HANA Transformation and DTP
3457265
CVSS
5.4

Affected system type ABAP
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-34690] Missing Authorization check in SAP Student Life Cycle Management (SLcM)
3425571
CVSS
5.3

Affected system type Java
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-28164] Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures)
3441817
CVSS
3.7

Affected system type BI/BO platform
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-34684] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Scheduling)
3455438
CVSS
9.8

Affected system type SAP Commerce Cloud
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2019-17495] Multiple vulnerabilities in SAP CX Commerce
3448171
CVSS
9.6

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33006] File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
3431794
CVSS
8.1

Affected system type BI/BO platform
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-28165] Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
3448445
CVSS
6.5

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-34687] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application server for ABAP and ABAP Platform
3450286
CVSS
6.1

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-32733] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
3460772
CVSS
6.1

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33002] Cross-Site Scripting (XSS) Vulnerability in SAP S/4HANA (Document Service Handler for DPS)
3447467
CVSS
5.5

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-32731] Missing Authorization check in SAP My Travel Requests
3349468
CVSS
4.9

Affected system type Sybase platform
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33008] Memory Corruption vulnerability in SAP Replication Server
3449093
CVSS
4.3

Affected system type BI/BO platform
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33004] Insecure Storage vulnerability in SAP BusinessObjects Business Intelligence Platform (Webservices)
3434666
CVSS
4.3

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [Multiple CVEs] Missing Authorization Checks in SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)
1938764
CVSS
4.2

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33009] SQL injection vulnerability in SAP Global Label Management (GLM)
3446076
CVSS
3.5

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33007] Client-side script execution vulnerability in SAP UI5(PDFViewer)
3434839
CVSS
8.8

Affected system type Java
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-27899] Security misconfiguration vulnerability in SAP NetWeaver AS Java User Management Engine
3421384
CVSS
7.7

Affected system type BI/BO platform
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-25646] Information Disclosure vulnerability in SAP BusinessObjects Web Intelligence
3438234
CVSS
7.2

Affected system type ABAP
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-27901] Directory Traversal vulnerability in SAP Asset Accounting
3442741
CVSS
6.8

Affected system type SAP Edge Integration
Patchday 2024-04
Released on 2024/04/09
Description Stack overflow vulnerability on the component images of SAP Integration Suite (EDGE INTEGRATION CELL)
3442378
CVSS
6.5

Affected system type ABAP
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-28167] Missing Authorization check in SAP Group Reporting Data Collection (Enter Package Data)
3359778
CVSS
6.5

Affected system type Kernel
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-30218] Denial of service (DOS) vulnerability in SAP NetWeaver AS ABAP and ABAP Platform
3425188
CVSS
5.3

Affected system type Java
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-27898] Server-Side Request Forgery in SAP NetWeaver (tc~esi~esp~grmg~wshealthcheck~ear)
3421453
CVSS
4.8

Affected system type SAP Business Connector
Patchday 2024-04
Released on 2024/04/09
Description [Multiple CVEs] Cross-Site Scripting (XSS) vulnerabilities in SAP Business Connector
3427178
CVSS
4.3

Affected system type ABAP
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-30216] Missing Authorization check in SAP S/4 HANA (Cash Management)
3430173
CVSS
4.3

Affected system type ABAP
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-30217] Missing Authorization check in SAP S/4 HANA (Cash Management)
3425274
CVSS
9.4

Affected system type SAP Build Apps
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2019-10744] Code Injection vulnerability in applications built with SAP Build Apps
3433192
CVSS
9.1

Affected system type Java
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2024-22127] Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)
3410615
CVSS
7.5

Affected system type HANA platform
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2023-44487 ] Denial of service (DOS) in SAP HANA XS Classic and HANA XS Advanced
3414195
CVSS
7.2

Affected system type BI/BO platform
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2023-50164] Path Traversal Vulnerability in SAP BusinessObjects Business Intelligence Platform (Central Management Console)
3377979
CVSS
5.4

Affected system type Kernel
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2024-27902] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP, applications based on SAPGUI for HTML (WebGUI)
3425682
CVSS
5.3

Affected system type Java
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2024-25644] Information Disclosure vulnerability in SAP NetWeaver (WSRM)
3428847
CVSS
5.3

Affected system type Java
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2024-25645] Information Disclosure vulnerability in SAP NetWeaver (Enterprise Portal)
3434192
CVSS
5.3

Affected system type Java
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2024-28163] Information Disclosure vulnerability in SAP NetWeaver Process Integration (Support Web Pages)
3417399
CVSS
4.6

Affected system type ABAP
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2024-22133] Improper Access Control in SAP Fiori Front End Server
3419022
CVSS
4.3

Affected system type ABAP
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2024-27900]Missing Authorization check in SAP ABAP Platform
3420923
CVSS
9.1

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-22131] Code Injection vulnerability in SAP ABA (Application Basis)
3426111
CVSS
8.6

Affected system type Java
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-24743] XXE vulnerability in SAP NetWeaver AS Java (Guided Procedures)
3410875
CVSS
7.6

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-22130] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
3421659
CVSS
7.4

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-22132] Code Injection vulnerability in SAP IDES Systems
3424610
CVSS
7.4

Affected system type SAP Cloud Connector
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-25642] Improper Certificate Validation in SAP Cloud Connector
2637727
CVSS
6.3

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-24739] Missing authorization check in SAP Bank Account Management
3404025
CVSS
5.4

Affected system type SAP Enable Now
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-22129] Cross-Site Scripting (XSS) vulnerability in SAP Companion
3360827
CVSS
5.3

Affected system type Kernel
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-24740] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (SAP Kernel)
3396109
CVSS
4.7

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-22128] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Business Client for HTML
2897391
CVSS
4.3

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/01
Description [CVE-2024-24741] Missing Authorization check in SAP Master Data Governance Material
3237638
CVSS
4.3

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-25643] Missing authorization check in SAP Fiori app ("My Overtime Requests")
3158455
CVSS
4.1

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-24742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
3413475
CVSS
9.1

Affected system type SAP Edge Integration
Patchday 2024-01
Released on 2024/01/09
Description [Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell
3412456
CVSS
9.1

Affected system type BTP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA
3411869
CVSS
8.4

Affected system type ABAP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21737] Code Injection vulnerability in SAP Application Interface Framework (File Adapter)
3389917
CVSS
7.5

Affected system type Kernel
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2023-44487] Denial of service (DOS) in SAP Web Dispatcher, SAP NetWeaver Application server ABAP, and ABAP Platform
3386378
CVSS
7.4

Affected system type SAP GUI / Frontend
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-22125] Information Disclosure vulnerability in Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge)
3407617
CVSS
7.3

Affected system type ABAP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21735] Improper Authorization check in SAP LT Replication Server
3260667
CVSS
6.4

Affected system type ABAP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21736] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)
3387737
CVSS
4.1

Affected system type ABAP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21738] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform
3392626
CVSS
4.1

Affected system type Kernel / Web Dispatcher
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-22124] Information Disclosure vulnerability in SAP NetWeaver Internet Communication Manager
3190894
CVSS
3.7

Affected system type SAP Marketing
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21734] URL Redirection vulnerability in SAP Marketing (Contacts App)