SAP Security Notes: October 2021 Summary

In October 2021, SAP released critical security updates addressing vulnerabilities across the NetWeaver, SAP Commerce, and Supply Chain Management platforms. These patches resolve high-priority security flaws, including broken authorization checks and XML External Entity (XXE) injection vulnerabilities, which could lead to unauthorized code execution or privilege escalation. What was the most critical update in October […]

SAP Security Notes: September 2021 Summary

In September 2021, SAP released critical security updates addressing high-priority vulnerabilities across the NetWeaver, Knowledge Management, and Contact Center platforms. These patches resolve severe risks, including remote code execution, OS command injection, and improper input handling, requiring immediate attention from security administrators to protect SAP landscapes. What was the most critical update in September 2021? […]

SAP Security Notes: August 2021 Summary

In August 2021, SAP released critical security updates addressing high-priority vulnerabilities across SAP NetWeaver, SAP S/4HANA, and SAP Business One. These patches resolve severe risks, including Server-Side Request Forgery (SSRF), SQL injection, and authentication bypasses, which could potentially lead to full system compromise if left unaddressed. What were the key SAP security updates in August […]

SAP Security Notes: July 2021 Summary

In July 2021, SAP released critical security updates addressing vulnerabilities in SAP NetWeaver and the ABAP Platform. These patches resolve high-priority security risks, including broken authentication, missing authorization checks, and potential denial-of-service vectors, requiring immediate attention from security administrators to maintain system integrity. What were the key SAP security updates in July 2021? The July […]

SAP Security Notes: June 2021 Summary

In June 2021, SAP released critical security updates addressing vulnerabilities across SAP Commerce, SAP NetWeaver ABAP, and SAP NetWeaver AS Java. These patches resolve high-priority risks, including remote code execution, memory corruption, and unauthorized file system access, requiring immediate attention from security administrators. What is the critical remote code execution risk in SAP Commerce? Hot […]

SAP Security Notes: May 2021 Summary

In May 2021, SAP released critical security patches addressing high-priority vulnerabilities across SAP NetWeaver AS ABAP, SAP Business One, and SAP Process Integration. These updates resolve significant risks including code injection, OS command injection, and information disclosure, requiring immediate action from security teams to prevent system compromise. What were the key SAP security updates in […]

SAP Security Notes: April 2021 Summary

In April 2021, SAP released critical security updates addressing high-priority vulnerabilities across SAP Business Warehouse (BW), SAP Commerce, and SAP NetWeaver AS Java. These patches resolve severe risks, including remote code injection, privilege escalation, and information disclosure, requiring immediate attention from security administrators to maintain system integrity. What were the key SAP security updates in […]

SAP Security Notes, March 2021

Hot news note 3022622 patches a critical code injection vulnerability in SAP Manufacturing Integration and Intelligence (MII). SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). Attackers can target this feature to inject malicious JSP code that include OS commands. The code and commands are […]

SAP Security Notes, February 2021

Hot News note 3014121 patches a critical remote code execution vulnerability in SAP Commerce. The Backoffice application in SAP Commerce enables certain users with required privileges to edit drools rules. An authenticated attacker with this privilege is able to inject malicious code in the drools rules, enabling the attacker to compromise the SAP host. This […]

SAP Security Notes, January 2021

Hot News note 2983367 corrects a code injection vulnerability in Master Data Management in SAP Business Warehouse and SAP BW4HANA. The vulnerability could be exploited to execute privileged OS commands. The correction introduces a hard coded report name which can only be executed by a legitimate user in release 7.30. The note removes the impacted […]