Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update 1 to Security Note 1723641, SAP security note 1747140

Description

This SAP Note supplements the corrections given with security note 1723641. Additional corrections are provided with the following Support Package Patch Levels:
XI Adapter Framework Core 3.0, SP20, Patch Level 47

Available fix and Supported packages

  • SAP-XIAFC | 3.0 | 3.0
  • XI ADAPTER FRAMEWORK CORE 3.0 | SP020 | 000047

Affected component

    BC-XI-CON-AFW
    J2EE Adapter Framework

CVSS

Score: 0

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1747140

TAGS

#XXE
#XML-eXternal-Entity
#information-disclosure
#Denial-of-Service
#DoS
#XI-Adapter-Framework
#XI-SOAP-Adapter
#update
#update-note

Explore More

SAP Security Patch Day – September 2025

SAP has released its September 2025 security patch package containing 26 security notes addressing critical vulnerabilities across enterprise SAP environments. This release

SAP Security Patch Day – August 2025

SAP has released its August 2025 security patch package containing 19 security notes addressing critical vulnerabilities across enterprise SAP environments. This release