Multiple SAP Products Patched for Critical Vulnerabilities (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- SQL injection in SAP S/4HANA Enterprise Search and HANA Deployment Infrastructure
- Configuration flaw in SAP Commerce Cloud enables code execution
- OS command execution in SAP Forecasting & Replenishment and NetWeaver ABAP
- XSS in SAP Business Server Pages and NetWeaver Application Server ABAP
- Log4j vulnerability with missing TLS verification
"SAP has released patches for multiple critical vulnerabilities in products including S/4HANA, Commerce Cloud, and NetWeaver. The vulnerabilities cover SQL injection, configuration flaws, OS command execution, XSS, CSRF, and code injection. A related Log4j vulnerability for missing TLS verification has also been reported. Organizations are advised to apply updates as soon as possible."
no comments yet.