HomeSecuritySAP Marketing patches critical vulnerabilities

SAP Marketing patches critical vulnerabilities

Ten new security notes were released this week by SAP, as part of the September 2020 Security Patch Day, as well as updates to 6 previous security notes.

SAP

Two of the updates address critical flaws in SAP Marketing – Mobile Channel Servlet (CVE-2020-6320 – improper access control) and NetWeaver (ABAP Server) and ABAP Platform (CVE-2020-6318 – code injection), which have CVSS scores of 9.6 and 9.1, respectively.

The Mobile Channel Servlet allows for the creation of mobile campaigns ,in which push notifications are sent to Android and iOS via Google Firebase. The critical flaw addressed this week allowed an attacker to gain access to limited functionality.

"An exploit of the vulnerability allows an attacker to perform operations related to contact and interaction data," explains Onapsis, a company specializing in Oracle and SAP application security.

The code injection flaw in NetWeaver could allow an attacker to take complete control of the application. Thus, the attacker could view, change, or delete data via code injected into memory and executed by the application, or could cause the application to terminate.

SAP has also fixed two other flaws, one of which allows a missing authorization check in Solution Manager (CVE-2020-6207, CVSS score 10) and another that deals with security updates for the Chromium browser in the Business Client (CVSS score of 9.8).

Two other security updates address high-severity vulnerabilities, namely code injection in NetWeaver (ABAP) and ABAP Platform (CVE-2020-6296) and a server-side request forgery in NetWeaver AS ABAP (CVE-2020-6275).

Five security notes released this week address moderate severity vulnerabilities in Bank Analyzer and S/4HANA Financial Products (CVE-2020-6311), Commerce (CVE-2020-6302), NetWeaver AS ABAP (CVE-2020-6324), NetWeaver AS Java (CVE-2020-6326), and Fiori (Launchpad) (CVE-2020-6283).

Two other updates address multiple vulnerabilities in BusinessObjects Business Intelligence Platform (CVE-2020-6325, CVE-2020-6312, and CVE-2020-6288) and 3D Visual Enterprise Viewer (38 CVEs).

This week, SAP also released updates for two bugs : one addresses cross-site scripting (XSS) vulnerabilities in modified jQuery bundled with SAPUI5 (CVE-2020-11022, CVE-2020-11023) and another fixes server request forgery in NetWeaver AS JAVA (CVE-2020-6282).

SAP also announced a low-severity security update that fixes an information disclosure vulnerability in Adaptive Server Enterprise (CVE-2020-6317).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS