SAP Prodjct Suite May 2024 Security Patch Advisory

Overview

 

SAP has announced an update to address vulnerabilities. Users of the affected versions are advised to update to the latest version.

 

Affected Products

 

CVE-2024-37177

  • SAP Financial Consolidation FINANCE 1010 version

 

CVE-2024-34688

  • SAP NetWeaver AS Java MMR_SERVER 7.5 version

 

Resolved Vulnerabilities

 

XSS Vulnerability in the SAP Financial Consolidation product (CVE-2024-37177)

Denial of Service (DOS) vulnerability in the SAP NetWeaver AS Java product (CVE-2024-34688)

 

Vulnerability Patches

 

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites[1] to update to the latest Vulnerability Patches version.

 

Referenced Sites

 

[1] SAP Security Patch Day – June 2024

https://support.sap.com/en/my-support/knowledge-base/security-notes-news/june-2024.html

[2] cve-2024-37177

https://www.cve.org/CVERecord?id=CVE-2024-37177

[3] cve-2024-34688

https://www.cve.org/CVERecord?id=CVE-2024-34688