Search Icon

SAP Security Notes Review: September 2023

12 September 2023

banner image

Overview

SAP’s security patch day for September 2023 has seen the release of 16 OSS SAP security notes. Overall, five notes have been classified as critical, two as high, seven as medium, and one as low based on CVSS v3.0 Rating

September 2023 CVSS v3 Base Score Graph
Four notes have been released for:

  • SAP BusinessObjects Business Intelligence Platform

Three notes have been released for:

  • SAP S/4HANA

Two notes have been released for:

  • SAP CommonCrytoLib

Lastly, single notes have been released for:

  • SAP NetWeaver AS Java
  • SAP Business Client
  • SAP BusinessObjects Suite
  • SAP NetWeaver AS ABAP
  • SAP Quotation Management Insurance
  • SAP NetWeaver (Guided Procedures)
  • SAP PowerDesigner Client

September 2023 Product Category Graph

Vulnerabilities: September 2023 Highlights

[CVE-2023-40309] Missing Authorisation check in SAP CommonCryptoLib (SAP Note 3340576)

SAP CommonCryptoLib does not perform necessary authentication checks, resulting in missing or wrong authorisation checks for an authenticated user and escalating privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group and therefore read, modify, or delete restricted data.

[CVE-2023-40308] Memory Corruption vulnerability in SAP CommonCryptoLib (SAP Note 3327896)

An unauthenticated attacker can exploit SAP CommonCryptoLib to craft a request that, when submitted to an open port, causes a memory corruption error in a library, which in turn causes the target component to crash, making it unavailable.

[CVE-2023-40624] Code Injection vulnerability in SAP NetWeaver AS ABAP (applications based on Unified Rendering) (SAP Note 3323163)

An attacker can inject and execute JavaScript code in a web application via SAP NetWeaver AS ABAP (applications based on Unified Rendering). Thus, they could control the behaviour of said web application.

[CVE-2023-40625] Missing Authorization check in Manage Purchase Contracts App (SAP Note 3326361) (SAP Note 3326361)

The Manage Purchase Contracts App does not perform necessary authorization checks for an authenticated user. This as a result allows an attacker to perform unintended actions resulting in the escalation of privileges, which has a low impact on confidentiality and integrity with no impact on the system’s availability.

 

Related Blogs

AI-First SAP SuccessFactors AMS Blog Banner Image

01 September 2026

Reimagining SuccessFactors Support: From Tickets to Intelligence: An AI-First AMS Model

SAP SuccessFactors Agentic AI: Joule and AI Agents

24 August 2026

SAP SuccessFactors - From Systems of Record to Systems of Intelligence

Pricefx blog banner

21 August 2026

"We Already Have a CRM." Why That Isn't a Pricing Strategy.

Leveraging claude in sap successfactors

17 August 2026

Leveraging claude in sap successfactors

AI-embedded SAP Blog banner

29 July 2026

AI Built In, Not Bolted On: What AI-Embedded AMS Actually Looks Like

Rethinking blog banner

28 July 2026

Rethinking Application Managed Services for HR Shared Services

successfactor blog banner

22 July 2026

Is Your SAP SuccessFactors Environment Ready for SAP Business AI and Joule?

Pricefx Certified

13 July 2026

Beyond the Platform: Why Certified Pricefx Experts Make the Difference