SAP Releases January 2023 Security Updates
Scheduled security updates address critical vulnerabilities affecting multiple products
Summary
Scheduled security updates address critical vulnerabilities affecting multiple products
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
- SAP Host Agent (Windows)
- SAP Business Planning and Consolidation MS
- SAP NetWeaver Process Integration
- SAP Bank Account Management (Manage Banks)
Threat details
Introduction
SAP has released security updates to address multiple vulnerabilities, which are covered in nine new security notes and three updates to previous notes. Seven of these vulnerabilities are rated Critical and involve issues such as SQL injection, code injection, improper access control, capture replay and insecure deserialisation of untrusted data. An attacker could exploit some of these vulnerabilities to take control of an affected system.
Remediation advice
Affected organisations are encouraged to review the SAP Security Notes for January 2023 and apply the necessary updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 11 January 2023 2:40 pm