SAP Alert
2894Warning Date
Severity Level
Warning Number
Target Sector
12 April, 2023
● Critical
2023-5545
All
SAP has released security updates to address multiple vulnerabilities in the following products:
- SAP NetWeaver (BI CONT ADD ON)
- SAP NetWeaver AS for ABAP and ABAP Platform
- SAP BusinessObjects Business Intelligence Platform (Promotion Management)
- SAP NetWeaver AS Java (User Defined Search)
- SAP Diagnostics Agent
Attacker could exploit these vulnerabilities by doing the following:
- Improper Access Control
- Arbitrary Code Execution
- Path Traversal
- Information Disclosure
The CERT team encourages users to review SAP security advisory and apply the necessary updates by logging in to the below page: