menu
close
close

Experienced a potential cyberattack or suspicious activity?

What are you looking for?
close
  • published 1/21/25 10:13 AM
  • updated 14 January 2025
  • 3 Min read

Security Updates - SAP

Alert Rating

Critical

Audience

Corporations, Government

On this page

Security Updates - SAP

SAP released 14 new Security Notes as part of its monthly Security Patch Day. These patches address critical vulnerabilities in various SAP products and components, improving the overall security posture of SAP environments. The vulnerabilities covered in this update could potentially allow attackers to exploit security weaknesses, leading to unauthorized access, data breaches, or system disruptions.

 

Critical Vulnerabilities:

  • CVE-2025-0070 (Note 3537476): Affects SAP NetWeaver ABAP Server and Platform. Improper authentication may allow unauthorized access, posing a severe risk.
  • CVE-2025-0066 (Note 3550708): Affects the Internet Communication Framework in SAP NetWeaver AS ABAP, exposing sensitive information.

High Severity Vulnerabilities:

  • SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform (CVE-2025-0063, CVSS 8.8)
  • Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform (CVE-2025-0061 and CVE-2025-0060, CVSS 8.7)
  • DLL Hijacking vulnerability in SAPSetup (CVE-2025-0069, CVSS 7.8)
     

Take Action

Protect yourself

The UAE Cyber Security Council recommends checking the SAP Support Portal and apply the patches on a priority

Attachments

Stay Connected

Follow our channels
Follow our social media channels to stay up to date.
Social Icon Social Icon Social Icon Social Icon Social Icon

Take Action

Spread Awareness

Share this threat to raise awareness and help others stay alert

GET INVOLVED

Make a Difference
Get involved with CSC and play a part in safeguarding the UAE's digital landscape.

Other Threats

20 January 2025

Alert rating

Critical

Critical Vulnerability in F5 Traffix SDC

A critical vulnerability has been discovered in F5 Traffix SDC, linked to Apache Tomcat, which could allow attackers to gain unauthorized access to compromised systems.

Protecting

Corporations, Government

share share

17 January 2025

Alert rating

High

Security Updates - NVIDIA

NVIDIA has released security updates to address multiple vulnerabilities in the NVIDIA Container Toolkit and NVIDIA GPU Operator.

Protecting

Corporations, Government

share share

16 January 2025

Alert rating

Critical

Critical Vulnerability in FortiSwitch Devices

A critical vulnerability (CVE-2023-37936) has been discovered in multiple versions of Fortinet FortiSwitch devices. This vulnerability, classified as a use of hard-coded cryptographic key [CWE-321], allows a remote unauthenticated attacker in possession of the key to execute unauthorized code via crafted cryptographic request.

Protecting

Corporations, Government

share share