SAP Releases December 2020 Security Updates
Affected platforms
The following platforms are known to be affected:
NetWeaver AS JAVA Versions: 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50
BusinessObjects BI Platform (Crystal Report) Versions: 4.1, 4.2, 4.3
Business Warehouse Versions: 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782
Solution Manager Versions: 7.20
NetWeaver AS ABAP Versions: 740, 750, 751, 752, 753, 754
Disclosure Management Versions: 10.1
HANA database Versions: 2.0
S4 HANA Versions: 101, 102, 103, 104, 105
Threat details
Introduction
SAP has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system. These include a missing authentication check vulnerability affecting SAP NetWeaver AS JAVA (P2P Cluster Communication).
Remediation advice
Organisations are encouraged to review the SAP Security Notes for December 2020 and apply the necessary updates.
Last edited: 10 December 2020 12:30 pm