Skip to main content

SAP Releases December 2020 Security Updates

Report a cyber attack: call 0300 303 5222 or email [email protected]

Affected platforms

The following platforms are known to be affected:

NetWeaver AS JAVA Versions: 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50

BusinessObjects BI Platform (Crystal Report) Versions: 4.1, 4.2, 4.3

Business Warehouse Versions: 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782

Solution Manager Versions: 7.20

NetWeaver AS ABAP Versions: 740, 750, 751, 752, 753, 754

Disclosure Management Versions: 10.1

HANA database Versions: 2.0

S4 HANA Versions: 101, 102, 103, 104, 105 


Threat details

Introduction

SAP has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system. These include a missing authentication check vulnerability affecting SAP NetWeaver AS JAVA (P2P Cluster Communication).


Remediation advice

Organisations are encouraged to review the SAP Security Notes for December 2020 and apply the necessary updates.

Last edited: 10 December 2020 12:30 pm