SAP Alert
2285Warning Date
Severity Level
Warning Number
Target Sector
9 August, 2023
● Critical
2023-5719
All
Description:
SAP has released security updates to address multiple vulnerabilities in the following products:
- SAP PowerDesigner
- SAP Commerce Cloud
- SAP Business One
- SAP BusinessObjects Business Intelligence (installer)
- SAP BusinessObjects Business Intelligence Platform
- SAP Message Server
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Improper authentication
- Command Injection
- Cross-Site Scripting (XSS)
- Denial of Service (DoS)
- Improper Authorization
- SQL Injection
- Information Disclosure
Best practice and Recommendations:
The CERT team encourages users to review SAP security advisory and apply the necessary updates by logging in to the below page: