The SAP Security Year ends with a relatively small number of new and updated SAP Security Notes. With only 14 notes, it is far below this years average of 20. Almost 50% of the issues are rated as HotNews or High Priority notes. SAP NetWeaver AS JAVA vulnerabilities allow an unauthenticated attacker to perform different privileged actions, such as changing database connection parameters or performing a Denial-of-Service attack. SAP Security Note #2974774, tagged with a CVSS score of 10, patches the aforementioned vulnerabilities. SAP is explicitly referring to its 24 months rule, stating that security patches will only be provided for support packages not older than 24 months.”]
Source: https://onapsis.com/blog/sap-security-notes-december-2020

