We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 12 and the highest CVSS score is 9.8.

 

Severity
SAP© Security advisories 12
 System Types
Affected SAP© system types

 

3479478
CVSS
9.8

Affected system type BI/BO platform
Patchday 2024-10
Released on 2024/08/13
Description [CVE-2024-41730] Missing Authentication check in SAP BusinessObjects Business Intelligence Platform
3523541
CVSS
8.0

Affected system type SAP Enterprise...
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2022-23302] Multiple vulnerabilities in SAP Enterprise Project Connection
3478615
CVSS
7.7

Affected system type BI/BO platform
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2024-37179] Insecure File Operations vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)
3495876
CVSS
6.5

Affected system type Sybase platform
Patchday 2024-10
Released on 2024/08/13
Description [Multiple CVEs] Multiple vulnerabilities in SAP Replication Server (FOSS)
3477359
CVSS
6.0

Affected system type Java
Patchday 2024-10
Released on 2024/09/10
Description [CVE-2024-45283] Information disclosure vulnerability in SAP NetWeaver AS for Java (Destination Service)
3507545
CVSS
5.4

Affected system type SAP Commerce / SAP...
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2024-45278] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice
3503462
CVSS
5.4

Affected system type Java
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2024-47594] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC)
3481588
CVSS
4.3

Affected system type ABAP
Patchday 2024-10
Released on 2024/09/10
Description [CVE-2024-41729] Information Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer)
3520100
CVSS
4.3

Affected system type SAP HANA Client
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2024-45277] Prototype Pollution vulnerability in SAP HANA Client
3251893
CVSS
4.3

Affected system type ABAP
Patchday 2024-10
Released on 2024/09/24
Description [CVE-2024-45282] HTTP Verb Tampering in SAP S/4 HANA(Manage Bank Statements)
3479293
CVSS
4.3

Affected system type ABAP
Patchday 2024-10
Released on 2024/08/13
Description [CVE-2024-42373] Missing Authorization Check in SAP Student Life Cycle Management (SLcM)
3454858
CVSS
4.1

Affected system type ABAP
Patchday 2024-10
Released on 2024/07/09
Description [CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform