SAP Alert

Warning Date
Severity Level
Warning Number
Target Sector
12 September, 2023
● Critical
2023-5791
All
Description:
SAP has released security updates to address multiple vulnerabilities in the following products:
- SAP CommonCryptoLib
- SAP NetWeaver AS ABAP
- SAP NetWeaver AS Java and ABAP Platform of S/4HANA on-premise
- SAP Web Dispatcher
- SAP Content Server
- SAP HANA Database
- SAP Host Agent
- SAP Extended Application Services and Runtime (XSA)
- SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)
- SAP BusinessObjects Business Intelligence Platform (Promotion Management)
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Improper Access Control
- Information Disclosure
- Elevate Privileges
- Denial of Service (DoS)
Best practice and Recommendations:
The CERT team encourages users to review SAP security advisory and apply the necessary updates by logging in to the below page: