
SAP has released patches for 14 new security notes and three updates to previously released notes as part of its May 2024 Security Patch Day.
The most significant advisory addresses a critical vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform, tracked as CVE-2024-33006, with a CVSS score of 9.6. This vulnerability allows an unauthenticated attacker to upload a malicious file to the server, potentially leading to complete system compromise when accessed by a victim.
Also, two other critical vulnerabilities, identified as CVE-2019-17495 (CSS Injection) with a CVSS score of 9.8 and CVE-2022-36364 (RCE) with a CVSS score of 8.8, were also addressed in SAP CX Commerce.
A high-priority note was released to address CVE-2024-28165, a cross-site scripting (XSS) vulnerability in the SAP BusinessObjects Business Intelligence Platform, with a CVSS score of 8.1. This vulnerability could allow attackers to inject malicious scripts into web pages viewed by other users, leading to potential data breaches.
The remaining notes address various medium- and low-severity vulnerabilities across a range of SAP products, including:
- SAP S/4HANA
- SAP My Travel Requests
- SAP Replication Server
- SAP BusinessObjects Business Intelligence Platform
- SAP Global Label Management
- SAP Bank Account Management
- SAP UI5
Organizations using SAP products are strongly encouraged to apply these patches promptly to mitigate potential risks and ensure the integrity of their systems.
Summary
| SAP Note | Type | Description | Priority |
| 2622660 | Update | Security updates for the browser control Google Chromium delivered with SAP Business Client BC-FES-BUS-DSK | HotNews |
| 3455438 | New | [CVE-2019-17495] Multiple vulnerabilities in SAP CX Commerce CEC-SCC-PLA-PL | HotNews |
| 3448171 | New | [CVE-2024-33006] File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform BC-SRV-KPR-CMS | HotNews |
| 3431794 | New | [CVE-2024-28165] Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform BI-BIP-INV | High |
| 3448445 | New | [CVE-2024-34687] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application server for ABAP and ABAP Platform BC-SRV-GBT-GOS | Medium |
| 3441944 | Update | [CVE-2024-32730] Missing authorization check in SAP Enable Now Manager KM-SEN-MGR | Medium |
| 3460772 | New | [CVE-2024-33002] Cross-Site Scripting (XSS) Vulnerability in SAP S/4HANA (Document Service Handler for DPS) BC-EIM-ESH | Medium |
| 3450286 | New | [CVE-2024-32733] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform BC-MID-AC | Medium |
| 3447467 | New | [CVE-2024-32731] Missing Authorization check in SAP My Travel Requests FI-TV-ODT-MTR | Medium |
| 2745860 | Update | Information Disclosure in Enterprise Services Repository of SAP Process Integration BC-XI-IBD-INF | Medium |
| 3349468 | New | [CVE-2024-33008] Memory Corruption vulnerability in SAP Replication Server BC-SYB-REP | Medium |
| 3449093 | New | [CVE-2024-33004] Insecure Storage vulnerability in SAP BusinessObjects Business Intelligence Platform (Webservices) BI-BIP-INV | Medium |
| 3434666 | New | [Multiple CVEs] Missing Authorization Checks in SAP S/4 HANA (Manage Bank Statement Reprocessing Rules) FI-FIO-AR-PAY | Medium |
| 2174651 | Update | Potential information disclosure relating to PI Integration Directory BC-XI-IBC | Medium |
| 1938764 | New | [CVE-2024-33009] SQL injection vulnerability in SAP Global Label Management (GLM) EHS-SAF-GLM | Medium |
| 3392049 | New | [CVE-2024-33000] Missing Authorization check in SAP Bank Account Management FIN-FSCM-CLM-BAM | Low |
| 3446076 | New | [CVE-2024-33007] Client-side script execution vulnerability in SAP UI5(PDFViewer) CA-UI5-SC | Low |


