SAP releases fixes for some serious flaws in its business software

Concept art representing cybersecurity principles
Nytt DDoS-rekord (Image credit: Shutterstock / ZinetroN)

Business software vendor SAP has recently patched various flaws across multiple products, including some vulnerabilities rated as “critical”. Altogether, 19 flaws were addressed.

The critical flaws include those that can allow threat actors to overwrite files, inject code, and access and manipulate data. Among the affected applications are SAP NetWeaver AS for Java, SAP NetWeaver Application Server for ABAP, SAP NetWeaver AP for ABAP and the SAP Business Objects Business Intelligence Platform.

For the remaining 14 vulnerabilities, four were deemed high-severity, and ten were deemed medium-severity. SAP is a popular software vendor among corporations, which makes it a major target for cybercriminals. 

Major target

SAP is the largest ERP vendor worldwide, retaining almost a quarter of the global market share (24%) with more than 400,000 customers. Furthermore, nine out of ten of the Forbes Global 2000 organizations use SAP products, including its customer relationship management (CRM) and supply chain management (SCM) solutions.

Despite its popularity in the business world, news of breaches via SAP products are few and far between. Just over a year ago, the US Cybersecurity and Infrastructure Security Agency (CISA) warned business users of a number of “severe vulnerabilities” found in SAP solutions, which could result in data theft and ransomware attacks. 

And last year, networks belonging to firms and government organizations were compromised in an attack on SAP systems that were unpatched, serving as a staunch reminder to apply security fixes to software as soon as they are released by the vendor. 

The same advice applies to this new case, so make sure to patch your SAP systems as soon as possible.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Representational image depecting cybersecurity protection
Ivanti reveals major security update, so make sure you're protected
The best free firewall
Sophos hotfixes remote code execution vulnerabilities in Firewall
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
Cyber-security
Adobe releases software updates to patch security issues
Image depicting a hand on a scanner
Hackers are targeting unpatched ServiceNow instances that exploit 3 separate year-old vulnerabilities
Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost