SAP Alert
2226Warning Date
Severity Level
Warning Number
Target Sector
11 July, 2023
● Critical
2023-5662
All
SAP has released security updates to address multiple vulnerabilities in the following products:
- SAP ECC
- SAP S/4HANA (IS-OIL)
- SAP NetWeaver
- SAP Web Dispatcher
- SAP UI5 Variant Management
- SAP SQL Anywhere
- SAP Solution Manager
Attacker could exploit these vulnerabilities by doing the following:
- Command Injection
- Path Traversal
- HTTP Request Smuggling attack
- Server-Side Request Forgery (SSRF)
- Memory Corruption
- Denial of Service (DoS)
The CERT team encourages users to review SAP security advisory and apply the necessary updates by logging in to the below page: