Security News > 2021 > May > SAP Patches High-Severity Flaws in Business One, NetWeaver Products

SAP Patches High-Severity Flaws in Business One, NetWeaver Products
2021-05-12 03:46

The first of the updated Hot News notes deals with security updates for Chromium delivered with SAP Business Client - at version 90.0.4430.93, this Chromium update fixes 63 security holes.

Of the high-severity security notes, two resolve three vulnerabilities in SAP Business One, all related to SAP's Chef Cookbooks, explained Onapsis, a firm that specializes in securing Oracle and SAP applications.

The first two flaws impact Business One for SAP HANA and could lead to code injection, allowing an attacker to take full control of the application, while the third affects Business One on SQL Server, and could lead to the disclosure of payroll data.

The third high-severity security note addresses a code injection issue in NetWeaver AS ABAP that could allow an attacker with access to the local SAP system to read and overwrite data, or launch a denial of service attack.

The medium-severity security notes patch vulnerabilities in SAP Commerce and Process Integration, while the low-severity note resolves a bug in SAP GUI for Windows.

The May 2021 SAP Security Patch Day also saw the release of updates for two medium-severity vulnerabilities affecting NetWeaver Application Server Java and SAP Focused RUN, respectively.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/f59MA_V0Tes/sap-patches-high-severity-flaws-business-one-netweaver-products

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
SAP 329 25 680 386 113 1204