Vulnerabilities Resolved in Multiple SAP Products (advisories.ncsc.nl)
- SAP patches multiple security vulnerabilities across its product suite.
- Flaws include remote code execution, information disclosure, and XSS.
- NCSC advisory urges organizations to apply patches promptly.
"The Dutch National Cyber Security Centre (NCSC) reports that SAP has fixed multiple vulnerabilities across its product portfolio, including SAP NetWeaver, SAProuter, and SAP Commerce Cloud. The flaws range from memory corruption and HTTP request smuggling to remote code execution and authentication bypass. Some vulnerabilities require authentication, while others can be exploited by unauthenticated attackers. The patches address issues in components like Apache Camel and Apache Tomcat. Organizations using affected SAP products are advised to apply security updates."
no comments yet.