ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Exploits

Seven Vulnerabilities Patched in SAP Products

Paul by Paul
October 9, 2014
in Exploits, Security
Reading Time: 1 min read
Share on FacebookShare on Twitter

SAP (Systems, Applications & Products in Data Processing) widely used in enterprises across the world had seven exploits patched in three of it’s products today.  If the bugs were exploited, which weren’t revealed until the other day, it could expose those operating systems to specialized attacks, information disclosure and in some cases, total compromise over the impacted system.

The vulnerabilities, which all are remotely exploitable, impact the German software company’s database management system HANA, its enterprise software BusinessObjects and analytics software NetWeaver Business Warehouse.

Businesses mainly utilize the software to maintain everything enterprise: sales, finances, human resources, and so forth. Officials with Onapsis Research Labs who identified the vulnerabilities, warn the bugs could reveal tons of data, customer information, product pricing, fiscal reports, employee details and a slew of other information.

Numerous cross-site scripting vulnerabilities both in HANA and BusinessObjects were also discovered that might have allowed an attacker to impersonate a legitimate user and attack others within the system.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

How Hackers Still Manage to Compromise MFA

Anthropic Unveils Claude Code Security to Detect and Fix Critical Vulnerabilities

The majority of the bugs were found way back in January by Will Vandevanter and Nahuel D. Sanchez, two analysts at Onapsis, a Cambridge, Mass.-based company. In accordance with information published Wednesday on its Security Advisories page, a lot of the bugs were fixed in June but specifics regarding them weren’t published until recently.

If users haven’t done so by now, both SAP and Onapsis are encouraging users to patch the affected software ASAP to prevent what it’s calling ‘business risks.’

“I would urge all SAP HANA and SAP BusinessObjects users to check our advisories and the remedial steps we share to protect their company’s most important data,” Ezequiel Gutesman, Onapsis Manager of Research, mentioned Wednesday.

Tags: exploitsSAPvulnerability
Previous Post

Chase Bank hacked 83 Million Impacted

Next Post

Apple Users targeted in Phishing Campaign

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026

Anthropic Unveils Claude Code Security to Detect and Fix Critical Vulnerabilities

February 22, 2026

Phishing 2.0: How AI is Turning Cyber Attacks into a Science

January 7, 2025 - Updated on January 9, 2025

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

December 25, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.