We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 12 and the highest CVSS score is 9.8.

 

Severity
SAP© Security advisories 12
 System Types
Affected SAP© system types

 

3455438
CVSS
9.8

Affected system type SAP Commerce Cloud
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2019-17495] Multiple vulnerabilities in SAP CX Commerce
3448171
CVSS
9.6

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33006] File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
3431794
CVSS
8.1

Affected system type BI/BO platform
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-28165] Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
3448445
CVSS
6.5

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-34687] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application server for ABAP and ABAP Platform
3460772
CVSS
6.1

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33002] Cross-Site Scripting (XSS) Vulnerability in SAP S/4HANA (Document Service Handler for DPS)
3450286
CVSS
6.1

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-32733] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
3447467
CVSS
5.5

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-32731] Missing Authorization check in SAP My Travel Requests
3349468
CVSS
4.9

Affected system type Sybase platform
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33008] Memory Corruption vulnerability in SAP Replication Server
3449093
CVSS
4.3

Affected system type BI/BO platform
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33004] Insecure Storage vulnerability in SAP BusinessObjects Business Intelligence Platform (Webservices)
3434666
CVSS
4.3

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [Multiple CVEs] Missing Authorization Checks in SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)
1938764
CVSS
4.2

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33009] SQL injection vulnerability in SAP Global Label Management (GLM)
3446076
CVSS
3.5

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33007] Client-side script execution vulnerability in SAP UI5(PDFViewer)