SAP Alert
3038Warning Date
Severity Level
Warning Number
Target Sector
10 November, 2022
● High
2022-5354
All
SAP has released security updates to address multiple vulnerabilities in the following products:
- SAP BusinessObjects Business Intelligence Platform
- SAPUI5
- SAP NetWeaver Application Server ABAP and ABAP
- SAP SuccessFactors attachment API for Mobile Application(Android & iOS)
- SAP Commerce
- SAP 3D Visual Enterprise Author and SAP 3D Visual Enterprise Viewer
An attacker could exploit these vulnerabilities by doing the following:
- Denial of service (DoS)
- Bypass authentication
- Information Disclosure
- Session hijack
- Execute arbitrary code
The CERT team encourages users to review SAP security advisory and apply the necessary updates by logging in to the below page: