Search Icon

SAP Security Notes Review: December 2024

10 December 2024

banner image

Overview

SAP’s security patch day for December 2024 has seen the release of 13 OSS SAP security notes. One note has been classified as critical, four as high, six as medium, and two as low based on CVSS v3.0 Rating.

Dec 24 CVSS v3 Base Score Graph

Two notes have been released for:

  • SAP NetWeaver Application Server for ABAP and ABAP Platform

Three notes have been released for:

  • SAP BusinessObjects

Single notes have been released for:

  • SAP NetWeaver AS for JAVA (Adobe Document Services)
  • SAP Web Dispatcher
  • SAP NetWeaver Application Server ABAP
  • SAP NetWeaver Administrator (System Overview)
  • SAP NetWeaver AS JAVA
  • SAP HCM
  • SAP Product Lifecycle Costing
  • SAP Commerce Cloud

Dec 24 Product Category Graph

Vulnerabilities: December 2024 Highlights

[CVE-2024-47585] Missing Authorisation check in SAP NetWeaver Application Server for ABAP and ABAP Platform (SAP Note 3536361)

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorisation checks, which results in privilege escalation. While authorisations for import and export are distinguished, a single authorisation is applied for both, which may contribute to these risks.

[CVE-2022-47578]  Multiple vulnerabilities in SAP NetWeaver AS for JAVA (Adobe Document Services)  (SAP Note 3536965)

Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application.

About this Review

On the second Tuesday of each month, SAP release security updates to their software products. At Applexus, we analyse all of the released security updates and produce this security review, including sending bespoke recommendations for each of our managed service customers.

There is more information on how we handle SAP security updates, including information on SAP’s process, the CVE process and the CVSS base scores in our earlier article on addressing security vulnerabilities in SAP software.

Related Blogs

Fashion S/4HANA Migration: Clean Core vs Customization

05 June 2026

One Size Doesn't Fit All: Lessons from Two Fashion S/4HANA Migrations

cloud-erp-for-uk-retailers-blog-banner

31 March 2026

Why UK Retailers Can’t Afford to Wait on Cloud ERP

Business Case for SAP S4HANA in the Age of AI Banner

24 March 2026

Business Case for SAP S4HANA in the Age of AI

SAP Security Notes Review: November 2025

17 November 2025

SAP Security Notes Review: November 2025

Modern ERP system streamlining fashion and retail operations across channels

10 November 2025

Why Modern ERP is No Longer Optional for Fashion & Retail Success

Banner illustrating S/4HANA migration strategies tailored for mid-market companies comparing transformation and selective migration approaches

04 November 2025

Choosing the Right S/4HANA Migration for Mid-Market Companies

SAP Security Notes Review: Oct 2025

30 October 2025

SAP Security Notes Review: October 2025

The Rise of Autonomous AI in Business

25 September 2025

Making S/4HANA Migration Simple for Mid-Market Businesses with MVP+