Application Security

SAP Patches High-Severity Vulnerabilities in PDCE, Commerce

Patch Tuesday: Enterprise software vendor SAP releases patches for high-severity vulnerabilities in multiple products and tools.

SAP

Enterprise software maker SAP on Tuesday announced the release of 16 new and two updated security notes as part of its July 2024 patch day, including two notes dealing with high-severity vulnerabilities.

The most severe of the issues is a missing authorization check in PDCE (Product Design Cost Estimating), a lifecycle costing tool. Tracked as CVE-2024-39592 (CVSS score of 7.7/10), the bug could allow an attacker to read generic table data, according to SAP.

The second high-priority note resolves CVE-2024-39597 (CVSS score of 7.2/10), an improper authorization check in SAP Commerce that could provide attackers with access to improperly configured sites.

“An attacker can misuse the forgotten password functionality to gain access to a site for which early login and registration is activated, without requiring the merchant to approve the account beforehand,” according to a separate advisory from application security firm Onapsis.

“If the site is not configured as an isolated site, this can also grant access to other non-isolated early login sites, even if registration is not enabled for those other sites,” the company added.

Of the remaining SAP security notes (PDF), 15 are described as medium-severity issues in Landscape Management, Document Builder, NetWeaver, CRM, Business Warehouse, S/4HANA, Business Workflow, GUI for Windows, Transportation Management, and Enable Now.

Advertisement. Scroll to continue reading.

The patched vulnerabilities include information disclosure issues, unrestricted file uploads, missing authorization checks, cross-site scripting (XSS), and server-side request forgery (SSRF) bugs.

SAP makes no mention of any of these vulnerabilities being exploited in the wild. However, users are advised to update their appliances as soon as possible, as attackers are known to have targeted security defects in SAP products for which patches had been released.

Related: SAP Patches High-Severity Vulnerabilities in Financial Consolidation, NetWeaver

Related: Fortra Patches Critical SQL Injection in FileCatalyst Workflow

Related: Atlassian Patches High-Severity Vulnerabilities in Confluence, Crucible, Jira

Related: F5 Patches Dangerous Vulnerabilities in BIG-IP Next Central Manager

Related Content

Vulnerabilities

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components.

Vulnerabilities

Intel has informed customers about several high-severity vulnerabilities that can lead to privilege escalation and even code execution.

Vulnerabilities

A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.

Vulnerabilities

The security defects could be exploited for arbitrary code execution and denial-of-service.

Vulnerabilities

SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs.

ICS/OT

The industrial giants fixed dozens of vulnerabilities across their ICS products, with advisories also released by CISA and VDE CERT.

Vulnerabilities

Two flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed.

Vulnerabilities

The ColdFusion security defects could allow attackers to execute arbitrary code or elevate their privileges.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version