SAP's April 2024 Updates Patch High-Severity Vulnerabilities

Enterprise software maker SAP on Tuesday announced the release of 10 new and two updated security notes, including three notes that address high-severity vulnerabilities.
Of SAP's April 2024 security notes, the most severe addresses a security misconfiguration issue in NetWeaver AS Java User Management Engine.
The UME allows users to self-register and modify their profiles, but the two optional features do not adhere to the existing password requirements, accepting simple passwords instead. The two features are disabled by default and customers can enable either or both.
The security firm recommends applying SAP's patches regardless of whether the features are enabled or not.
SAP on Tuesday also addressed a high-severity information disclosure flaw in BusinessObjects Web Intelligence, and a high-severity directory traversal bug in Asset Accounting.
The remaining eight new security notes released on SAP's April 2024 Security Patch Day address medium-severity issues in Integration Suite, NetWeaver, Group Reporting Data Collection, Business Connector, and S/4HANA. On Tuesday, SAP also announced updates to a May 2022 security note addressing an information disclosure flaw in Employee Self Service, and an August 2023 note resolving a URL redirection bug in S/4HANA. Customers are advised to apply the patches as soon as possible.
While the vendor makes no mention of any of these vulnerabilities being exploited in attacks, SAP vulnerabilities for which patches have been released are known to have been targeted in the wild.


This Cyber News was published on www.securityweek.com. Publication date: Tue, 09 Apr 2024 14:43:05 +0000


Cyber News related to SAP's April 2024 Updates Patch High-Severity Vulnerabilities