SAP NetWeaver & CX Commerce Weakness Allows Total Takeover

May 16, 2024
1 min read

TLDR:

  • Three critical vulnerabilities have been discovered in SAP Customer Experience (CX) commerce cloud and SAP NetWeaver Application
  • The vulnerabilities include CSS injection, file upload, and remote code execution

Eswar’s article highlights the critical vulnerabilities found in the SAP Customer Experience (CX) commerce cloud and SAP NetWeaver Application. These vulnerabilities include CSS injection, file upload, and remote code execution, with severity levels ranging from Critical to High. The vulnerabilities have been assigned CVE numbers and have been patched by SAP as part of the HotNews update for May 2024.

The article goes into detail about each vulnerability, explaining how they can be exploited by threat actors and the potential risks they pose to users. It emphasizes the importance of upgrading to the latest versions and applying necessary patches to prevent exploitation.

Overall, Eswar’s article serves as a warning to users of these products and provides valuable information on how to protect against potential cyber threats.

Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat

Cyber insurance evolves to cover all your online needs

TLDR: Cyber insurance coverage is evolving to help raise security baselines across businesses. Only one-quarter of companies have a standalone cyber insurance policy. In today’s evolving cybersecurity landscape, cyber insurance coverage is