Vulnerabilities

SAP’s April 2024 Updates Patch High-Severity Vulnerabilities

SAP has released 12 new and updated security notes on April 2024 Security Patch Day, including three notes dealing with high-severity vulnerabilities.

SAP has released 12 new and updated security notes on April 2024 Security Patch Day, including three notes dealing with high-severity vulnerabilities.

Enterprise software maker SAP on Tuesday announced the release of 10 new and two updated security notes, including three notes that address high-severity vulnerabilities.

Of SAP’s April 2024 security notes, the most severe addresses a security misconfiguration issue (CVE-2024-27899, CVSS score of 8.8) in NetWeaver AS Java User Management Engine (UME).

The UME allows users to self-register and modify their profiles, but the two optional features do not adhere to the existing password requirements, accepting simple passwords instead. The two features are disabled by default and customers can enable either or both.

“The title of the assigned vulnerability seems to be a little bit misleading since the vulnerability is not caused by a configuration issue but by a missing check in the program logic,” enterprise software security firm Onapsis explains.

The security firm recommends applying SAP’s patches regardless of whether the features are enabled or not.

SAP on Tuesday also addressed a high-severity information disclosure flaw in BusinessObjects Web Intelligence (rooted in insufficient validation checks when uploading Excel files), and a high-severity directory traversal bug in Asset Accounting.

Advertisement. Scroll to continue reading.

The remaining eight new security notes released on SAP’s April 2024 Security Patch Day address medium-severity issues in Integration Suite, NetWeaver, Group Reporting Data Collection, Business Connector, and S/4HANA.

On Tuesday, SAP also announced updates to a May 2022 security note addressing an information disclosure flaw in Employee Self Service, and an August 2023 note resolving a URL redirection bug in S/4HANA.

Customers are advised to apply the patches as soon as possible. While the vendor makes no mention of any of these vulnerabilities being exploited in attacks, SAP vulnerabilities for which patches have been released are known to have been targeted in the wild.

Related: SAP Patches Critical Command Injection Vulnerabilities

Related: SAP Patches Critical Vulnerability Exposing User, Business Data

Related: SAP’s First Patches of 2024 Resolve Critical Vulnerabilities

Related: SAP Patches Critical Vulnerability in Business Technology Platform

Related Content

Vulnerabilities

The flaws could lead to the disclosure of sensitive information, memory corruption, and disruption of normal system usage.

Vulnerabilities

The flaws could allow attackers to inject malicious code, leading to information disclosure and code execution.

Supply Chain Security

The compromised Lightning and Intercom packages have a combined monthly download count of nearly 10 million.

Malware & Threats

The Mini Shai-Hulud attack introduced a preinstall hook to fetch and execute a Bun binary and bypass security monitoring.

Vulnerabilities

The company has released 19 new security notes addressing flaws in over a dozen enterprise products.

Vulnerabilities

A code injection bug in FS-QUO and an insecure deserialization flaw in NetWeaver could lead to arbitrary code execution.

Vulnerabilities

SAP has released 26 new and one updated security notes on February 2026 security patch day.

Vulnerabilities

SAP has released 17 security notes, including four that address critical SQL injection, RCE, and code injection vulnerabilities.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version