- published 1/21/25 10:13 AM •
- updated 14 January 2025 •
- 3 Min read
Security Updates - SAP
Alert Rating
Audience
Corporations, Government
On this page
Security Updates - SAP
Critical Vulnerabilities:
- CVE-2025-0070 (Note 3537476): Affects SAP NetWeaver ABAP Server and Platform. Improper authentication may allow unauthorized access, posing a severe risk.
- CVE-2025-0066 (Note 3550708): Affects the Internet Communication Framework in SAP NetWeaver AS ABAP, exposing sensitive information.
High Severity Vulnerabilities:
- SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform (CVE-2025-0063, CVSS 8.8)
- Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform (CVE-2025-0061 and CVE-2025-0060, CVSS 8.7)
- DLL Hijacking vulnerability in SAPSetup (CVE-2025-0069, CVSS 7.8)
Take Action
Protect yourself
The UAE Cyber Security Council recommends checking the SAP Support Portal and apply the patches on a priority
GET INVOLVED
Make a Difference
Other Threats
20 January 2025
Critical Vulnerability in F5 Traffix SDC
A critical vulnerability has been discovered in F5 Traffix SDC, linked to Apache Tomcat, which could allow attackers to gain unauthorized access to compromised systems.
Protecting
Corporations, Government
17 January 2025
NVIDIA has released security updates to address multiple vulnerabilities in the NVIDIA Container Toolkit and NVIDIA GPU Operator.
Protecting
Corporations, Government
16 January 2025
Critical Vulnerability in FortiSwitch Devices
A critical vulnerability (CVE-2023-37936) has been discovered in multiple versions of Fortinet FortiSwitch devices. This vulnerability, classified as a use of hard-coded cryptographic key [CWE-321], allows a remote unauthenticated attacker in possession of the key to execute unauthorized code via crafted cryptographic request.
Protecting
Corporations, Government