SAP Security Notes: December 2021 Summary
In December 2021, SAP released comprehensive security updates primarily focused on the critical Log4Shell (CVE-2021-44228) remote code execution vulnerability. This flaw, affecting the Apache Log4j 2 library, presented a severe risk to enterprise environments, requiring immediate patching and mitigation across multiple SAP solutions. Understanding the Log4Shell Vulnerability (CVE-2021-44228) Log4Shell is a critical vulnerability in the […]
SAP Security Notes: November 2021 Summary
In November 2021, SAP released critical security updates addressing vulnerabilities across several key platforms, including SAP NetWeaver, SAP Solution Manager, and SAP Commerce. These patches resolve high-priority risks such as SQL injection, privilege escalation, and unauthorized access, requiring immediate attention from security administrators to maintain landscape integrity. What were the key SAP security updates in […]
SAP Security Notes: October 2021 Summary
In October 2021, SAP released critical security updates addressing vulnerabilities across the NetWeaver, SAP Commerce, and Supply Chain Management platforms. These patches resolve high-priority security flaws, including broken authorization checks and XML External Entity (XXE) injection vulnerabilities, which could lead to unauthorized code execution or privilege escalation. What was the most critical update in October […]
SAP Security Notes: September 2021 Summary
In September 2021, SAP released critical security updates addressing high-priority vulnerabilities across the NetWeaver, Knowledge Management, and Contact Center platforms. These patches resolve severe risks, including remote code execution, OS command injection, and improper input handling, requiring immediate attention from security administrators to protect SAP landscapes. What was the most critical update in September 2021? […]
SAP Security Notes: August 2021 Summary
In August 2021, SAP released critical security updates addressing high-priority vulnerabilities across SAP NetWeaver, SAP S/4HANA, and SAP Business One. These patches resolve severe risks, including Server-Side Request Forgery (SSRF), SQL injection, and authentication bypasses, which could potentially lead to full system compromise if left unaddressed. What were the key SAP security updates in August […]
SAP Security Notes: July 2021 Summary
In July 2021, SAP released critical security updates addressing vulnerabilities in SAP NetWeaver and the ABAP Platform. These patches resolve high-priority security risks, including broken authentication, missing authorization checks, and potential denial-of-service vectors, requiring immediate attention from security administrators to maintain system integrity. What were the key SAP security updates in July 2021? The July […]
SAP Security Notes: June 2021 Summary
In June 2021, SAP released critical security updates addressing vulnerabilities across SAP Commerce, SAP NetWeaver ABAP, and SAP NetWeaver AS Java. These patches resolve high-priority risks, including remote code execution, memory corruption, and unauthorized file system access, requiring immediate attention from security administrators. What is the critical remote code execution risk in SAP Commerce? Hot […]
SAP Security Notes: May 2021 Summary
In May 2021, SAP released critical security patches addressing high-priority vulnerabilities across SAP NetWeaver AS ABAP, SAP Business One, and SAP Process Integration. These updates resolve significant risks including code injection, OS command injection, and information disclosure, requiring immediate action from security teams to prevent system compromise. What were the key SAP security updates in […]
SAP Security Notes: April 2021 Summary
In April 2021, SAP released critical security updates addressing high-priority vulnerabilities across SAP Business Warehouse (BW), SAP Commerce, and SAP NetWeaver AS Java. These patches resolve severe risks, including remote code injection, privilege escalation, and information disclosure, requiring immediate attention from security administrators to maintain system integrity. What were the key SAP security updates in […]
SAP Security Notes, March 2021
Hot news note 3022622 patches a critical code injection vulnerability in SAP Manufacturing Integration and Intelligence (MII). SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). Attackers can target this feature to inject malicious JSP code that include OS commands. The code and commands are […]