CERT-In Advisory
CIAD-2024-0022
Multiple Vulnerabilities in SAP Products
Original Issue Date: April 11, 2024
Severity Rating: High
Software Affected
- SAP NetWeaver AS Java (User Management Engine)
- SAP BusinessObjects Web Intelligence
- SAP Asset Accounting
- SAP Edge Integration Cell
- SAP NetWeaver AS ABAP and ABAP Platform
- SAP Group Reporting Data Collection (Enter Package Data)
- SAP Employee Self Service (Fiori My Leave Request)
- SAP S/4 HANA (Manage Catalog Items and Cross-Catalog search)
- SAP NetWeaver
- SAP Business Connector
- SAP S/4 HANA (Cash Management)
Overview
Multiple vulnerabilities have been reported in SAP Products which could allow an attacker to perform Stack overflow, Denial of service (DOS), URL redirection, Server-Side Request Forgery, Cross-Site Scripting (XSS), Improper Certificate Validation, Information disclosure, Missing authorization check and Directory Traversal on the targeted system.
Description
Multiple vulnerabilities have been reported in SAP products; details of which are provided below:

Solution
Apply appropriate fixes as mentioned in SAP Security Advisory:
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/april-2024.html
Vendor Information
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/april-2024.html
References
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/april-2024.html
CVE Name
CVE-2024-27899
CVE-2024-25646
CVE-2024-27901
CVE-2024-30218
CVE-2024-28167
CVE-2022-29613
CVE-2023-40306
CVE-2024-27898
CVE-2024-30214
CVE-2024-30215
CVE-2024-30216
CVE-2024-30217
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|