CERT-In Advisory
CIAD-2024-0009
Multiple Vulnerabilities in SAP Products
Original Issue Date: February 15, 2024
Severity Rating: Critical
Software Affected
- SAP ABA (Application Basis)
- SAP NetWeaver AS Java (User Admin Application)
- SAP NetWeaver AS Java (Guided Procedures)
- SAP CRM WebClient UI
- IDES Systems
- SAP Cloud Connector
- SAP GUI for Windows and SAP GUI for Java
- BAM (Bank Account Management)
- SAP Companion
- SAP NetWeaver Application Server ABAP (SAP Kernel)
- SAP NWBC for HTML
- SAP Fiori app ("My Overtime Requests")
- SAP Master Data Governance Material
- SAP CRM (WebClient UI)
- SAP Master Data Governance
Overview
Multiple vulnerabilities have been reported in SAP Products which could allow an attacker to perform code injection, Cross Site Scripting (XSS), XML external entity injection (XXE), Improper Certificate Validation, Information disclosure, Missing authorization check and Directory Traversal on the targeted system.
Description
Multiple vulnerabilities have been reported in SAP products; details of which are provided below:

Solution
Apply appropriate fixes as mentioned in SAP Security Advisory:
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/february-2024.html
Vendor Information
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/february-2024.html
References
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/february-2024.html
CVE Name
CVE-2023-49058
CVE-2023-49580
CVE-2024-22126
CVE-2024-22128
CVE-2024-22129
CVE-2024-22130
CVE-2024-22131
CVE-2024-22132
CVE-2024-24739
CVE-2024-24740
CVE-2024-24741
CVE-2024-24742
CVE-2024-24743
CVE-2024-24742
CVE-2024-25643
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|