Skip to main content

SAP Releases June 2023 Security Updates

Scheduled security updates address vulnerabilities affecting multiple products

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled security updates address vulnerabilities affecting multiple products


Affected platforms

The following platforms are known to be affected:

The following platforms are also known to be affected:

  • SAP Knowledge Warehouse
  • SAP UI5 Variant Management
  • SAP Plant Connectivity
  • SAPUI5
  • SAP S/4HANA (Supplier Factsheet and Enterprise Search for Business Partner, Supplier and Customer)
  • SAP NetWeaver (Design Time Repository)
  • SAP NetWeaver Enterprise Portal
  • SAP CRM ABAP (Grantor Management)
  • SAP CRM (WebClient UI)
  • Master Data Synchronization (MDS COMPARE TOOL)
  • SAP NetWeaver (Change and Transport System)

Threat details

Introduction

SAP has released security updates to address multiple vulnerabilities, which are covered in eight new security notes and five updates to previous notes. Four vulnerabilities are rated as high priority, seven at medium and one at low. An attacker could exploit some of these vulnerabilities to perform privilege escalation, cross site scripting (XSS), denial-of-service, or other malicious activity.


Remediation advice

Affected organisations are encouraged to review the SAP Security Notes for June 2023 and apply the relevant security updates.



CVE Vulnerabilities

Last edited: 14 June 2023 5:08 pm