SAP Address Several Vulnerabilities with May 2024 Patch Day

SAP Address Several Vulnerabilities with May 2024 Patch Day


SAP has  released patches for 14 new security notes and three updates to previously released notes as part of its May 2024 Security Patch Day.

The most significant advisory addresses a critical vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform, tracked as CVE-2024-33006, with a CVSS score of 9.6. This vulnerability allows an unauthenticated attacker to upload a malicious file to the server, potentially leading to complete system compromise when accessed by a victim.

Advertisements

Also, two other critical vulnerabilities, identified as CVE-2019-17495 (CSS Injection) with a CVSS score of 9.8 and CVE-2022-36364 (RCE) with a CVSS score of 8.8, were also addressed in SAP CX Commerce.

A high-priority note was released to address CVE-2024-28165, a cross-site scripting (XSS) vulnerability in the SAP BusinessObjects Business Intelligence Platform, with a CVSS score of 8.1. This vulnerability could allow attackers to inject malicious scripts into web pages viewed by other users, leading to potential data breaches.

The remaining notes address various medium- and low-severity vulnerabilities across a range of SAP products, including:

  • SAP S/4HANA
  • SAP My Travel Requests
  • SAP Replication Server
  • SAP BusinessObjects Business Intelligence Platform
  • SAP Global Label Management
  • SAP Bank Account Management
  • SAP UI5

Organizations using SAP products are strongly encouraged to apply these patches promptly to mitigate potential risks and ensure the integrity of their systems.

Advertisements

Summary

SAP NoteTypeDescriptionPriority
2622660UpdateSecurity updates for the browser control Google Chromium delivered with SAP Business Client
BC-FES-BUS-DSK
HotNews
3455438New[CVE-2019-17495] Multiple vulnerabilities in SAP CX Commerce
CEC-SCC-PLA-PL
HotNews
3448171New[CVE-2024-33006] File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
BC-SRV-KPR-CMS
HotNews
3431794New[CVE-2024-28165] Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
BI-BIP-INV
High
3448445New[CVE-2024-34687] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application server for ABAP and ABAP Platform
BC-SRV-GBT-GOS
Medium
3441944Update[CVE-2024-32730] Missing authorization check in SAP Enable Now Manager
KM-SEN-MGR
Medium
3460772New[CVE-2024-33002] Cross-Site Scripting (XSS) Vulnerability in SAP S/4HANA (Document Service Handler for DPS)
BC-EIM-ESH
Medium
3450286New[CVE-2024-32733] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
BC-MID-AC
Medium
3447467New[CVE-2024-32731] Missing Authorization check in SAP My Travel Requests
FI-TV-ODT-MTR
Medium
2745860UpdateInformation Disclosure in Enterprise Services Repository of SAP Process Integration
BC-XI-IBD-INF
Medium
3349468New[CVE-2024-33008] Memory Corruption vulnerability in SAP Replication Server
BC-SYB-REP
Medium
3449093New[CVE-2024-33004] Insecure Storage vulnerability in SAP BusinessObjects Business Intelligence Platform (Webservices)
BI-BIP-INV
Medium
3434666New[Multiple CVEs] Missing Authorization Checks in SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)
FI-FIO-AR-PAY
Medium
2174651UpdatePotential information disclosure relating to PI Integration Directory
BC-XI-IBC
Medium
1938764New[CVE-2024-33009] SQL injection vulnerability in SAP Global Label Management (GLM)
EHS-SAF-GLM
Medium
3392049New[CVE-2024-33000] Missing Authorization check in SAP Bank Account Management
FIN-FSCM-CLM-BAM
Low
3446076New[CVE-2024-33007] Client-side script execution vulnerability in SAP UI5(PDFViewer)
CA-UI5-SC
Low

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.