SAP Alert
2640Warning Date
Severity Level
Warning Number
Target Sector
9 May, 2023
● Critical
2023-5581
All
SAP has released security updates to address multiple vulnerabilities in the following products:
- SAP 3D Visual Enterprise License Manager
- SAP Business Objects Intelligence Platform
- SAP AS NetWeaver JAVA
- SAP IBP EXCEL ADD-IN
- SAP Power Designer (Proxy)
- SAP Commerce
- SAP GUI for Windows
- SAPUI5
Attacker could exploit these vulnerabilities by doing the following:
- Session Hijacking
- Improper Authentication
- Arbitrary Code Execution
- Buffer Overflow
- Information Disclosure
- Improper Access Control
- Privilege Escalation
- Memory Corruption
- Denial of Service (DoS)
- Improper Neutralization
The CERT team encourages users to review SAP security advisory and apply the necessary updates by logging in to the below page: