SAP released security updates for 17 vulnerabilities across its product portfolio, including two critical flaws led by CVE-2024-41730 in SAP BusinessObjects Business Intelligence Platform. The vulnerability carries a CVSS 9.8 rating and can allow a remote, unauthenticated attacker to take full control of an affected system through the REST interface when SSO is enabled. The issue is tracked in the CVE program and was highlighted alongside broad remediation guidance urging customers to apply the latest patches immediately.
SAP also fixed CVE-2024-29415 in SAP Build Apps, a CVSS 9.1 server-side request forgery flaw tied to a Node.js component that improperly distinguishes public and private IP addresses. Additional patched issues across SAP products could enable code execution, cross-site scripting, SSRF, XML injection, privilege escalation, denial of service, unauthorized access to sensitive data, and authentication bypass, underscoring the risk to internet-exposed and enterprise SAP environments.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
SAP released security updates across its product portfolio to fix 17 vulnerabilities, including two rated critical. The fixes included CVE-2024-41730 in SAP BusinessObjects Business Intelligence Platform and CVE-2024-29415 in SAP Build Apps, and defenders were urged to update affected systems immediately.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.