SAP Security Notes: May 2023 Patch Summary

In May 2023, SAP released critical security updates addressing vulnerabilities across several platforms, most notably SAP BusinessObjects (BOBJ) and the SAP 3D Visual Enterprise License Manager. These updates include patches for information disclosure, code injection, broken authentication, and session hijacking risks that require immediate attention from security administrators. Executive Summary The May 2023 SAP security […]

SAP Security Notes: April 2023 Summary

In April 2023, SAP released several critical security notes addressing vulnerabilities in its software. Key patches included Note 3305369 for the SAP Diagnostics Agent, Note 3294595 for SAP NetWeaver AS ABAP, Note 3298961 for SAP BOBJ, and Note 3305907 for the BI Content Add-on for AS ABAP. The April 2023 SAP security update focused on […]

SAP Security Notes: March 2023 Vulnerability Summary

What are the critical SAP security vulnerabilities addressed in March 2023? In March 2023, SAP released patches for several high-risk vulnerabilities, including a critical SQL injection in NetWeaver AS Java, authentication bypasses in the LockingService, and code execution risks in SAP BusinessObjects Business Intelligence (BOBJ). These updates are essential for maintaining system integrity and preventing […]

SAP Security Notes: Critical Vulnerabilities and Updates for February 2023

The February 2023 SAP Security Notes address critical vulnerabilities across NetWeaver Application Server Java, the SAP Host Agent, and SAP BusinessObjects. Key patches include fixes for JNDI interface exposure, privilege escalation via webservice requests, and unrestricted file upload vulnerabilities, alongside necessary corrections for side effects introduced by earlier security patches. Executive Summary The February 2023 […]

SAP Security Notes: January 2023 Vulnerability Summary

The January 2023 SAP Security patch cycle addressed several critical and high-risk vulnerabilities, including a capture-replay issue in SAP NetWeaver AS ABAP and a broken authentication flaw in SAP NetWeaver AS Java. Organizations are advised to apply these security notes immediately to prevent unauthorized data access and potential service disruption. Executive Summary The January 2023 […]

SAP Security Notes, December 2022

In December 2022, SAP released critical security patches for vulnerabilities affecting SAP NetWeaver Application Server Java, SAP BusinessObjects, and SAP Commerce. These vulnerabilities include broken authentication, server-side request forgery, and remote code execution, requiring urgent implementation of security notes 3267780, 3273480, 3239475, and 3271523 to protect systems from exploitation. The December 2022 security updates addressed […]

SAP Security Notes, November 2022

The November 2022 SAP Security Notes address several critical and high-risk vulnerabilities, including a critical insecure deserialization flaw in the SAP BusinessObjects Business Intelligence Platform (BOBJ) and directory traversal issues in NetWeaver Application Server ABAP (AS ABAP). These updates are essential for maintaining the security of SAP environments. Executive Summary In November 2022, SAP released […]

SAP Security Notes, October 2022

In October 2022, SAP released security patches addressing multiple critical vulnerabilities, including a URL redirection flaw in SAP Commerce Cloud (Note 3239152), a directory traversal vulnerability in SAP Manufacturing Execution (Note 3242933), an information disclosure risk in SAP BusinessObjects, and a denial-of-service vulnerability in SAP SQL Anywhere and SAP IQ. Executive Summary SAP’s October 2022 […]

SAP Security Notes, September 2022

The September 2022 SAP Security Patch Day addressed several high-priority vulnerabilities across the SAP ecosystem, including critical flaws in SAP GRC Access Control, BusinessObjects (BOBJ), SAP Business One, and SAP SuccessFactors. These patches resolve risks related to unauthorized access, privilege escalation, and information disclosure. Executive Summary The September 2022 security updates from SAP targeted critical […]

SAP Security Notes, August 2022

Note 3102769 was rereleased in August with updated solution information. The workaround detailed in the original note has been moved to the new note 3221696. The workaround provides steps for deactivating the SAP IKS component to address a high priority cross-site scripting (XSS) vulnerability in SAP Knowledge Warehouse. Note 3150454 was also updated to enforce […]