SAP Prodjct Suite May 2024 Security Patch Advisory
Overview
SAP has announced an update to address vulnerabilities. Users of the affected versions are advised to update to the latest version.
Affected Products
CVE-2024-37177
- SAP Financial Consolidation FINANCE 1010 version
CVE-2024-34688
- SAP NetWeaver AS Java MMR_SERVER 7.5 version
Resolved Vulnerabilities
XSS Vulnerability in the SAP Financial Consolidation product (CVE-2024-37177)
Denial of Service (DOS) vulnerability in the SAP NetWeaver AS Java product (CVE-2024-34688)
Vulnerability Patches
Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites[1] to update to the latest Vulnerability Patches version.
Referenced Sites
[1] SAP Security Patch Day – June 2024
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/june-2024.html
[2] cve-2024-37177
https://www.cve.org/CVERecord?id=CVE-2024-37177
[3] cve-2024-34688