SAP Product Security Update Advisory

Overview

An update has been released to address vulnerabilities inv SAP Products. Users of the affected versions are advised to update to the latest version.

 

Affected Products
 

CVE-2024-47590

SAP Web Dispatcher

  • WEBDISP 7.77
  • 7.89
  • 7.93
  • KERNEL 7.77
  • 9.12
  • 9.13

 

CVE-2024-47595

SAP Host Agent

  • SAPHOSTAGENT 7.22

 

 

Resolved Vulnerabilities

 

A user verification error in the Two-Factor Authentication REST API could allow login as an administrator account without authentication (CVE-2024-10924)

Vulnerability that could allow attackers in the local sapsys group to replace privilege-protected files, affecting the confidentiality and integrity of the application (CVE-2024-47595)

 

Vulnerability Patches

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-47590

  • See Referenced Sites[2] for updates

 

CVE-2024-47595

  • See Referenced Sites[4] for updates

 

 

Referenced Sites
 

[1] CVE-2024-47590 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-47590

[2] sap/notes/3520281

https://me.sap.com/notes/3520281

[3] CVE-2024-47595 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-47595

[4] sap/notes/3509619

https://me.sap.com/notes/3509619