Search Icon

SAP Security Notes Review: August 2023

08 August 2023

banner image

Overview

SAP’s security patch day for August 2023 has seen the release of 18 OSS SAP security notes. One note has been classified as critical, seven as high, eight as medium, and two as low based on CVSS v3.0 Rating.  

CVSS v3 Scores for August 23 Security Notes, bar chart

Three notes have been released for:

  • SAP Business One
  • SAP BusinessObjects5

Two notes have been released for:

  • SAP Commerce
  • SAP PowerDesigner
  • SAP SRM

Single notes have been released for:

  • SAP Host Agent
  • SAP Process Integration
  • SAP NetWeaver AS ABAP
  • SAP Kernel
  • SAP S/4HANA
  • SAPUI5

Product Category Security Notes for August 2023, bar chart

Vulnerabilities: August 2023 Highlights

[CVE-2023-37483] Multiple Vulnerabilities in SAP PowerDesigner (SAP Note 3341460)

Multiple security vulnerabilities have been identified in PowerDesigner Proxy. The first concerns improper access control hence allowing an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy. Further, the second potentially allows an attacker to access password hashes from the backend database.

[CVE-2023-39437] Cross-Site Scripting (XSS) vulnerability in SAP Business One (SAP Note 3358300)

An attacker could insert malicious code into the content of a web page or application and deliver it to the client due to a vulnerability in SAP Business One. This could subsequently lead to harmful actions affecting the Confidentiality, Integrity, and Availability of the application.

 [CVE-2023-39439] Improper authentication in SAP Commerce Cloud (SAP Note 3346500)

Certain configurations of SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication hence allowing users can log into the system without a passphrase.

[CVE-2023-37491] Improper Authorization check vulnerability in SAP Message Server (SAP Note 3344295)

Authenticated malicious users can bypass the ACL (Access Control List) of the SAP Message Server under certain conditions. As a result, they can enter the network of the SAP systems served by the attacked server.

About this Review

On the second Tuesday of each month, SAP release security updates to their software products. At Applexus, we analyse all of the released security updates and produce this security review, including sending bespoke recommendations for each of our managed service customers.

There is more information on how we handle SAP security updates, including information on SAP’s process, the CVE process and the CVSS base scores in our earlier article on addressing security vulnerabilities in SAP software.

Related Blogs

Fashion S/4HANA Migration: Clean Core vs Customization

05 June 2026

One Size Doesn't Fit All: Lessons from Two Fashion S/4HANA Migrations

cloud-erp-for-uk-retailers-blog-banner

31 March 2026

Why UK Retailers Can’t Afford to Wait on Cloud ERP

Business Case for SAP S4HANA in the Age of AI Banner

24 March 2026

Business Case for SAP S4HANA in the Age of AI

SAP Security Notes Review: November 2025

17 November 2025

SAP Security Notes Review: November 2025

Modern ERP system streamlining fashion and retail operations across channels

10 November 2025

Why Modern ERP is No Longer Optional for Fashion & Retail Success

Banner illustrating S/4HANA migration strategies tailored for mid-market companies comparing transformation and selective migration approaches

04 November 2025

Choosing the Right S/4HANA Migration for Mid-Market Companies

SAP Security Notes Review: Oct 2025

30 October 2025

SAP Security Notes Review: October 2025

The Rise of Autonomous AI in Business

25 September 2025

Making S/4HANA Migration Simple for Mid-Market Businesses with MVP+