Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

SAP’s April 2024 Updates Patch High-Severity Vulnerabilities

SAP has released 12 new and updated security notes on April 2024 Security Patch Day, including three notes dealing with high-severity vulnerabilities.

Enterprise software maker SAP on Tuesday announced the release of 10 new and two updated security notes, including three notes that address high-severity vulnerabilities.

Of SAP’s April 2024 security notes, the most severe addresses a security misconfiguration issue (CVE-2024-27899, CVSS score of 8.8) in NetWeaver AS Java User Management Engine (UME).

The UME allows users to self-register and modify their profiles, but the two optional features do not adhere to the existing password requirements, accepting simple passwords instead. The two features are disabled by default and customers can enable either or both.

“The title of the assigned vulnerability seems to be a little bit misleading since the vulnerability is not caused by a configuration issue but by a missing check in the program logic,” enterprise software security firm Onapsis explains.

The security firm recommends applying SAP’s patches regardless of whether the features are enabled or not.

SAP on Tuesday also addressed a high-severity information disclosure flaw in BusinessObjects Web Intelligence (rooted in insufficient validation checks when uploading Excel files), and a high-severity directory traversal bug in Asset Accounting.

Advertisement. Scroll to continue reading.

The remaining eight new security notes released on SAP’s April 2024 Security Patch Day address medium-severity issues in Integration Suite, NetWeaver, Group Reporting Data Collection, Business Connector, and S/4HANA.

On Tuesday, SAP also announced updates to a May 2022 security note addressing an information disclosure flaw in Employee Self Service, and an August 2023 note resolving a URL redirection bug in S/4HANA.

Customers are advised to apply the patches as soon as possible. While the vendor makes no mention of any of these vulnerabilities being exploited in attacks, SAP vulnerabilities for which patches have been released are known to have been targeted in the wild.

Related: SAP Patches Critical Command Injection Vulnerabilities

Related: SAP Patches Critical Vulnerability Exposing User, Business Data

Related: SAP’s First Patches of 2024 Resolve Critical Vulnerabilities

Related: SAP Patches Critical Vulnerability in Business Technology Platform

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In cyber-physical systems (CPS), just one hour of downtime can outweigh an entire annual security budget. Learn how to master the Return on Security Investment (ROSI) to align security goals with the bottom-line priorities.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Malwarebytes has named Chung Ip as Chief Financial Officer.

Semperis has appointed John Podboy as Chief Information Security Officer.

Randy Menon has become Chief Product and Marketing Officer at One Identity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.