SAP Product Security Update Advisory
Overview
An update has been released to address vulnerabilities inv SAP Products. Users of the affected versions are advised to update to the latest version.
Affected Products
CVE-2024-47590
SAP Web Dispatcher
- WEBDISP 7.77
- 7.89
- 7.93
- KERNEL 7.77
- 9.12
- 9.13
CVE-2024-47595
SAP Host Agent
- SAPHOSTAGENT 7.22
Resolved Vulnerabilities
A user verification error in the Two-Factor Authentication REST API could allow login as an administrator account without authentication (CVE-2024-10924)
Vulnerability that could allow attackers in the local sapsys group to replace privilege-protected files, affecting the confidentiality and integrity of the application (CVE-2024-47595)
Vulnerability Patches
Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2024-47590
- See Referenced Sites[2] for updates
CVE-2024-47595
- See Referenced Sites[4] for updates
Referenced Sites
[1] CVE-2024-47590 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-47590
[2] sap/notes/3520281
https://me.sap.com/notes/3520281
[3] CVE-2024-47595 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-47595
[4] sap/notes/3509619