We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 10 and the highest CVSS score is 9.1.

 

Severity
SAP© Security advisories 10
 System Types
Affected SAP© system types

 

3412456
CVSS
9.1

Affected system type BTP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA
3413475
CVSS
9.1

Affected system type SAP Edge Integration
Patchday 2024-01
Released on 2024/01/09
Description [Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell
3411869
CVSS
8.4

Affected system type ABAP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21737] Code Injection vulnerability in SAP Application Interface Framework (File Adapter)
3389917
CVSS
7.5

Affected system type Kernel
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2023-44487] Denial of service (DOS) in SAP Web Dispatcher, SAP NetWeaver Application server ABAP, and ABAP Platform
3386378
CVSS
7.4

Affected system type SAP GUI / Frontend
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-22125] Information Disclosure vulnerability in Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge)
3407617
CVSS
7.3

Affected system type ABAP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21735] Improper Authorization check in SAP LT Replication Server
3260667
CVSS
6.4

Affected system type ABAP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21736] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)
3387737
CVSS
4.1

Affected system type ABAP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21738] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform
3392626
CVSS
4.1

Affected system type Kernel / Web Dispatcher
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-22124] Information Disclosure vulnerability in SAP NetWeaver Internet Communication Manager
3190894
CVSS
3.7

Affected system type SAP Marketing
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21734] URL Redirection vulnerability in SAP Marketing (Contacts App)