SAP Security Patch Day – August 2024 (2024)

This post shares information on Security Notes that remediatesvulnerabilities discovered in SAP products. SAP strongly recommends that the customer applies patches on priority to protect their SAP landscape.

On 13th of August 2024, SAP Security Patch Day saw the release of 17 new Security Notes. Further, there were 8 updates to previously released Security Notes.

Note#
Title

Priority 

CVSS 

3479478

[CVE-2024-41730] Missing Authentication check in SAP BusinessObjects Business Intelligence Platform
Product - SAP BusinessObjects Business Intelligence Platform, Version – ENTERPRISE 430, 440

Hot News

9.8

3477196

[CVE-2024-29415] Server-Side Request Forgery vulnerability in applications built with SAP Build Apps
Product - SAP Build Apps, Versions < 4.11.130

Hot News

9.1

3485284

[CVE-2024-42374] XML injection in SAP BEx Web Java Runtime Export Web Service

Product- SAP BEx Web Java Runtime Export Web Service, Versions - BI-BASE-E 7.5, BI-BASE-B 7.5, BI-IBC 7.5, BI-BASE-S 7.5, BIWEBAPP 7.5

High

8.2

3423268

[CVE-2023-30533] Prototype Pollution in SAP S/4 HANA (Manage Supply Protection)

Product- SAP S/4 HANA, Library Versions - SheetJS CE < 0.19.3

High

7.8

3460407

Update to Security Note released on June 2024 Patch Day:

[CVE-2024-34688] Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)

Product- SAP NetWeaver AS Java, Version – MMR_SERVER 7.5

High 

7.5

3459935

[CVE-2024-33003] Information Disclosure Vulnerability in SAP Commerce Cloud

Product- SAP Commerce Cloud, Versions – HY_COM 1808, 1811, 1905, 2005, 2105, 2011, 2205, COM_CLOUD 2211

High 

7.4

3466801

Update to Security Note released on July 2024 Patch Day:

[CVE-2024-39593] Information Disclosure vulnerability in SAP Landscape Management

Product- SAP Landscape Management, Version - VCM 3.00

Medium 

6.9

3495876

[Multiple CVEs] Multiple vulnerabilities in SAP Replication Server (FOSS)

CVEs - CVE-2023-0215, CVE-2022-0778 , CVE-2023-0286

Product- SAP Replication Server, Versions – 16.0.3, 16.0.4

Medium 

6.5

3459379

Update to Security Note released on June 2024 Patch Day:

[CVE-2024-34683] Unrestricted file upload in SAP Document Builder (HTTP service)
Product - SAP Document Builder, Versions – S4CORE 100, 101, S4FND 102, 103, 104, 105, 106, 107, 108, SAP_BS_FND 702, 731, 746, 747, 748

Medium

6.5

3474590[CVE-2024-42376] Multiple Missing Authorization Check vulnerabilities in SAP Shared Service FrameworkAdditional CVE - CVE-2024-42377

Product- SAP Shared Service Framework, Versions – SAP_BS_FND 702, 731, 746, 747, 748

Medium 

6.5  

3438085[CVE-2024-33005] Missing Authorization check in SAP NetWeaver Application Server (ABAP and Java), SAP Web Dispatcher and SAP Content Server
Product- SAP NetWeaver Application Server (ABAP and Java), SAP Web Dispatcher and SAP Content Server, Versions – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, WEBDISP 7.53, 7.77, 7.85, 7.22_EXT, 7.89, 7.54, 7.93, KERNEL 7.22, 7.53, 7.77, 7.85, 7.89, 7.54, 7.93

Medium 

6.3  

3482217

Update to Security Note released on July 2024 Patch Day:

[CVE-2024-39594] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Business Warehouse - Business Planning and Simulation
Product- SAP Business Warehouse - Business Planning and Simulation, Versions – SAP_BW 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, SAP_BW_VIRTUAL_COMP 701

Medium 

6.1  

3465455

Update to Security Note released on June 2024 Patch Day:

[CVE-2024-37176] Missing Authorization check in SAP BW/4HANA Transformation and DTP
Product- SAP BW/4HANA Transformation and Data Transfer Process, Versions – DW4CORE 200, 300, 400, 796, SAP_BW 740, 750, 751, 752, 753, 754, 755, 756, 757, 758

Medium 

5.5  

3483256

[CVE-2024-41735] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice
Product – SAP Commerce Backoffice, Version – HY_COM 2205

Medium

5.4

3471450

[CVE-2024-41733] Information Disclosure Vulnerability in SAP Commerce
Product – SAP Commerce, Versions – HY_COM 2205, COM_CLOUD 2211

Medium

5.3

3487537[CVE-2024-41737] Server-Side Request Forgery (SSRF) in SAP CRM ABAP (Insights Management)
Product – SAP CRM ABAP (Insights Management), Versions – BBPCRM 700, 701, 702, 712, 713, 714

Medium

5.0

3458789

Update to Security Note released on July 2024 Patch Day:

[CVE-2024-34689] Server-Side Request Forgery in SAP Business Workflow (WebFlow Services) 
Product- SAP Business Workflow (WebFlow Services), Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758

Medium

5.0

3468102[CVE-2024-41732] Improper Access Control in SAP Netweaver Application Server ABAP
Product – SAP NetWeaver Application Server ABAP, Versions – SAP_UI 754, 755, 756, 757, 758, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 912
Medium

4.7

3150704

Update to Security Note released on January 2023 Patch Day:

[CVE-2023-0023] Information Disclosure in SAP Bank Account Management (Manage Banks)
Product – SAP Bank Account Management (Manage Banks), Versions – 800, 900

Medium

4.5

3433545

[CVE-2024-42375] Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform

Additional CVE - CVE-2024-28166, CVE-2024-41731

Product – SAP BusinessObjects Business Intelligence Platform, Versions – ENTERPRISE 420, 430, 440

Medium

4.3

3475427[CVE-2024-41736] Information Disclosure vulnerability in SAP Permit to Work
Product – SAP Permit to Work, Versions – UIS4HOP1 800, 900

Medium

4.3

3477423

[CVE-2024-39591] Missing Authorization check in SAP Document Builder
Product – SAP Document Builder, Versions – S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, S4FND 108, SAP_BS_FND 702, SAP_BS_FND 731, SAP_BS_FND 746, SAP_BS_FND 747, SAP_BS_FND 748

Medium

4.3

3479293

[CVE-2024-42373] Missing Authorization Check in SAP Student Life Cycle Management (SLcM)
Product – SAP Student Life Cycle Management (SLcM), Versions – IS-PS-CA 617, 618, 802, 803, 804, 805, 806, 807, 808

Medium

4.3

3494349

[CVE-2024-41734] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
Product – SAP NetWeaver Application Server ABAP and ABAP Platform, Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 912

Medium

4.3

3454858

Update to Security Note released on July 2024 Patch Day:

[CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Product- SAP NetWeaver Application Server for ABAP and ABAP Platform, Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758

Medium

4.1

To know more about the security researchers and research companies who have contributed for security patches of this month, visithere.

SAP is committed to delivering trustworthy products and cloud services. Secure configuration is essential to ensuring secure operation and data integrity. We have therefore documented security recommendations that are consolidated in this document to help you configure the best security for your SAP portfolio.

Archived blogs from previous years are available here.

If you have any comments or feedback about this post, you can write to secure@sap.com.

SAP Security Patch Day – August 2024 (2024)

References

Top Articles
Openingstijden Binnenstad Tilburg | Center of Tilburg
Bezoek winkels en musea in Tilburg | NS Dagje Uit | NS
Roblox Roguelike
Hotels
The Atlanta Constitution from Atlanta, Georgia
Nyu Paralegal Program
Kris Carolla Obituary
GAY (and stinky) DOGS [scat] by Entomb
Nier Automata Chapter Select Unlock
Suffix With Pent Crossword Clue
Minecraft Jar Google Drive
Letter F Logos - 178+ Best Letter F Logo Ideas. Free Letter F Logo Maker. | 99designs
使用 RHEL 8 时的注意事项 | Red Hat Product Documentation
Aris Rachevsky Harvard
Zack Fairhurst Snapchat
Best Mechanics Near You - Brake Masters Auto Repair Shops
Okc Body Rub
Sec Baseball Tournament Score
Sofia the baddie dog
Receptionist Position Near Me
R Baldurs Gate 3
Ardie From Something Was Wrong Podcast
Robotization Deviantart
Ups Drop Off Newton Ks
Pdx Weather Noaa
Kaiser Infozone
Stolen Touches Neva Altaj Read Online Free
Memberweb Bw
Iban's staff
Closest 24 Hour Walmart
Junee Warehouse | Imamother
PA lawmakers push to restore Medicaid dental benefits for adults
Otter Bustr
Mydocbill.com/Mr
Plead Irksomely Crossword
Levothyroxine Ati Template
How to Quickly Detect GI Stasis in Rabbits (and what to do about it) | The Bunny Lady
2132815089
Tableaux, mobilier et objets d'art
Quick Base Dcps
Darkglass Electronics The Exponent 500 Test
Kjccc Sports
Keci News
855-539-4712
1990 cold case: Who killed Cheryl Henry and Andy Atkinson on Lovers Lane in west Houston?
Shannon Sharpe Pointing Gif
Ty Glass Sentenced
Model Center Jasmin
Cryptoquote Solver For Today
Otter Bustr
Https://Eaxcis.allstate.com
7 National Titles Forum
Latest Posts
Article information

Author: Nicola Considine CPA

Last Updated:

Views: 5577

Rating: 4.9 / 5 (49 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Nicola Considine CPA

Birthday: 1993-02-26

Address: 3809 Clinton Inlet, East Aleisha, UT 46318-2392

Phone: +2681424145499

Job: Government Technician

Hobby: Calligraphy, Lego building, Worldbuilding, Shooting, Bird watching, Shopping, Cooking

Introduction: My name is Nicola Considine CPA, I am a determined, witty, powerful, brainy, open, smiling, proud person who loves writing and wants to share my knowledge and understanding with you.