DEV Community

Mark0
Mark0

Posted on

SAP warns of critical flaws in NetWeaver and Commerce Cloud

SAP has released its February 2024 Security Notes, addressing multiple critical vulnerabilities across its enterprise software suite. The updates specifically target high-severity flaws in SAP NetWeaver and SAP Commerce Cloud that could allow unauthenticated attackers to compromise systems or access sensitive data. These vulnerabilities underscore the critical nature of maintaining patch management for enterprise resource planning (ERP) systems.

The most severe flaw, identified as CVE-2024-22257, affects SAP Commerce Cloud and carries a CVSS score of 9.8. This vulnerability involves an improper authorization issue that could lead to complete system takeover. Additionally, SAP NetWeaver AS Java is affected by a code injection vulnerability (CVE-2024-22259) which allows attackers to execute arbitrary code. Organizations using these platforms are strongly advised to apply the provided security patches immediately to mitigate potential exploitation risks.


Read Full Article

Top comments (0)