News

SAP Issues Urgent Security Patch Day, Addressing 15 New Vulnerabilities

Giulio Saggin
Giulio Saggin
Tuesday 12 December 2023
SAP Issues Urgent Security Patch Day, Addressing 15 New Vulnerabilities
SAP

SAP's December 12, 2023 Security Patch Day unveiled a series of critical vulnerabilities across various SAP products. The release includes 15 new Security Notes and updates for previously released patches.

  • Note# 2622660 - Hot News (Priority 10.0): Addresses security updates for Google Chromium in SAP Business Client versions 6.5, 7.0, and 7.70.

  • Note# 3411067 - Hot News (Priority 9.1): Resolves Escalation of Privileges in SAP Business Technology Platform (BTP) Security Services Integration Libraries. CVEs addressed: CVE-2023-49583, CVE-2023-50422, CVE-2023-50423, CVE-2023-50424.

  • Note# 3399691 and 3350297 - Hot News (Priority 9.1): Updates addressing OS command injection vulnerabilities in SAP ECC and SAP S/4HANA (IS-OIL).

  • Note# 3394567 - High (Priority 8.1): Fixes an Improper Access Control vulnerability in SAP Commerce Cloud version 8.1.

  • Note# 3382353 - High (Priority 7.5): Addresses a Cross-site Scripting vulnerability in SAP BusinessObjects Business Intelligence Platform versions 420 and 430.

  • Note# 3385711 - High (Priority 7.3): Resolves an Information Disclosure vulnerability in SAP GUI for Windows and SAP GUI for Java, versions SAP_BASIS 755 to 758.

  • Note# 3406244 - High (Priority 7.1): Addresses a Missing Authorization Check in SAP EMARSYS SDK ANDROID version 3.6.2.

  • Note# 3369353 - Medium (Priority 6.8): Fixes a Cross Site Scripting vulnerability in SAP BusinessObjects Web Intelligence version 420.

  • Note# 3395306 - Medium (Priority 6.4): Resolves a Command Injection vulnerability in SAP Solution Manager version 720.

  • Note# 3383321 - Medium (Priority 6.1): Addresses a Cross-Site Scripting (XSS) vulnerability in SAP Biller Direct versions 635 and 750.

  • Note# 3217087 - Medium (Priority 6.1): Fixes a Cross-Site Scripting (XSS) vulnerability in SAP HCM (SMART PAYE solution) versions S4HCMCIE 100, SAP_HRCIE 600 to 608.

  • Note# 3159329 - Medium (Priority 5.3): Addresses a Denial of Service (DoS) vulnerability in the JSZip library bundled within SAPUI5 versions SAP_UI 750 to SAP_UI 756 and UI_700 200.

  • Note# 3406786 - Medium (Priority 4.3): Resolves a Client-Side Desynchronization vulnerability in SAP Fiori Launchpad versions SAP_UI 750 to SAP_UI 758 and SAP_BASIS 793.

  • Note# 3392547 - Medium (Priority 4.1): Addresses an SQL Injection vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform versions SAP_BASIS 700 to SAP_BASIS750.

  • Note# 3363690 - Low (Priority 3.5): Fixes a Directory Traversal vulnerability in SAP Master Data Governance and SAP Cloud Connector versions.

Users are strongly urged to apply these patches immediately to mitigate potential risks and ensure the integrity and security of their systems.

For more detailed information or comments, SAP encourages users to reach out via secure@sap.com.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203