SAP Security Notes Review: May 2024
14 May 2024

Overview
SAP’s security patch day for May 2024 has seen the release of 15 OSS SAP security notes. Two notes have been classified as critical, one as high, nine as medium, and two as low based on CVSS v3.0 Rating.

Three notes have been released for:
- SAP S/4HANA
- SAP NetWeaver AS ABAP
Two notes have been released for:
- SAP BusinessObjects
- SAP NetWeaver AS JAVA
Single notes have been released for:
- SAP Commerce
- SAP My Travel Requests
- SAPUI5
- SAP Replication Server
- SAP Global Label Management

Vulnerabilities: May 2024 Highlights
[CVE-2019-17495] Multiple vulnerabilities in SAP CX Commerce (SAP Note 3455438)
SAP Commerce uses the Swagger UI component, which is vulnerable to CSS injections. This vulnerability enables attackers to perform a Relative Path Overwrite (RPO) technique in the CSS-based input fields, posing high risks to the confidentiality, integrity, and availability of the application.
Included in the same note is a vulnerability with Apache Calcite Avatica. This can lead to remote code execution, which also poses a high risk to the confidentiality, integrity, and availability of the application.
[CVE-2024-33006] File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform (SAP Note 3448171)
An unauthenticated attacker can upload a malicious file to the server, which, when accessed by a victim, allows the attacker to compromise the system completely.
[CVE-2024-28165] Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform (SAP Note 3431794)
SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS. An attacker can manipulate a parameter in the OpenDocument URL, which could significantly impact the application’s confidentiality and integrity.







