Search Icon

SAP Security Notes Review: January 2024

09 January 2024

banner image

Overview

SAP’s security patch day for January 2024 has seen the release of 10 OSS SAP security notes. Two notes have been classified as critical, three as high, four as medium and one as low based on CVSS v3.0 Rating.

Bar chart for SAP Security Notes by CVSS v3 Base Score for Jan 2024

Three notes have been released for:

  • SAP NetWeaver AS ABAP

Single notes have been released for:

  • SAP BTP
  • SAP Web IDE
  • SAP Application Interface Framework
  • SAP LT Replication Server
  • SAP GUI
  • SAP S/4HANA
  • SAP Marketing

Bar Graph for Security Notes by Product Category for January 2024

Vulnerabilities: January 2024 Highlights

[Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell (SAP Note 3413475)

Under certain conditions, the SAP Edge Integration Cell, allows escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

[CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA (SAP Note 3412456)

Under certain conditions, node.js applications created through SAP Business Application Studio, SAP Web IDE Full-Stack or SAP Web IDE for SAP HANA are vulnerable to an escalation of privileges.

[CVE-2024-21737] Code Injection vulnerability in SAP Application Interface Framework (File Adapter) (SAP Note 3411869)

In SAP Application Interface Framework File Adapter, a highly privileged user can execute operating system commands using a function module. 

[CVE-2024-21735] Improper Authorisation check in SAP LT Replication Server (SAP Note 3407617)

SAP LT Replication Server does not perform necessary authorisation checks, which could escalate privileges.

About this Review

On the second Tuesday of each month, SAP release security updates to their software products. At Applexus, we analyse all of the released security updates and produce this security review, including sending bespoke recommendations for each of our managed service customers.

There is more information on how we handle SAP security updates, including information on SAP’s process, the CVE process and the CVSS base scores in our earlier article on addressing security vulnerabilities in SAP software.

Related Blogs

Fashion S/4HANA Migration: Clean Core vs Customization

05 June 2026

One Size Doesn't Fit All: Lessons from Two Fashion S/4HANA Migrations

cloud-erp-for-uk-retailers-blog-banner

31 March 2026

Why UK Retailers Can’t Afford to Wait on Cloud ERP

Business Case for SAP S4HANA in the Age of AI Banner

24 March 2026

Business Case for SAP S4HANA in the Age of AI

SAP Security Notes Review: November 2025

17 November 2025

SAP Security Notes Review: November 2025

Modern ERP system streamlining fashion and retail operations across channels

10 November 2025

Why Modern ERP is No Longer Optional for Fashion & Retail Success

Banner illustrating S/4HANA migration strategies tailored for mid-market companies comparing transformation and selective migration approaches

04 November 2025

Choosing the Right S/4HANA Migration for Mid-Market Companies

SAP Security Notes Review: Oct 2025

30 October 2025

SAP Security Notes Review: October 2025

The Rise of Autonomous AI in Business

25 September 2025

Making S/4HANA Migration Simple for Mid-Market Businesses with MVP+