Ten new security notes were released this week by SAP, as part of the September 2020 Security Patch Day, as well as updates to 6 previous security notes.

Two of the updates address critical flaws in SAP Marketing – Mobile Channel Servlet (CVE-2020-6320 – improper access control) and NetWeaver (ABAP Server) and ABAP Platform (CVE-2020-6318 – code injection), which have CVSS scores of 9.6 and 9.1, respectively.
The Mobile Channel Servlet allows for the creation of mobile campaigns ,in which push notifications are sent to Android and iOS via Google Firebase. The critical flaw addressed this week allowed an attacker to gain access to limited functionality.
"An exploit of the vulnerability allows an attacker to perform operations related to contact and interaction data," explains Onapsis, a company specializing in Oracle and SAP application security.
The code injection flaw in NetWeaver could allow an attacker to take complete control of the application. Thus, the attacker could view, change, or delete data via code injected into memory and executed by the application, or could cause the application to terminate.
SAP has also fixed two other flaws, one of which allows a missing authorization check in Solution Manager (CVE-2020-6207, CVSS score 10) and another that deals with security updates for the Chromium browser in the Business Client (CVSS score of 9.8).
Two other security updates address high-severity vulnerabilities, namely code injection in NetWeaver (ABAP) and ABAP Platform (CVE-2020-6296) and a server-side request forgery in NetWeaver AS ABAP (CVE-2020-6275).
Five security notes released this week address moderate severity vulnerabilities in Bank Analyzer and S/4HANA Financial Products (CVE-2020-6311), Commerce (CVE-2020-6302), NetWeaver AS ABAP (CVE-2020-6324), NetWeaver AS Java (CVE-2020-6326), and Fiori (Launchpad) (CVE-2020-6283).
Two other updates address multiple vulnerabilities in BusinessObjects Business Intelligence Platform (CVE-2020-6325, CVE-2020-6312, and CVE-2020-6288) and 3D Visual Enterprise Viewer (38 CVEs).
This week, SAP also released updates for two bugs : one addresses cross-site scripting (XSS) vulnerabilities in modified jQuery bundled with SAPUI5 (CVE-2020-11022, CVE-2020-11023) and another fixes server request forgery in NetWeaver AS JAVA (CVE-2020-6282).
SAP also announced a low-severity security update that fixes an information disclosure vulnerability in Adaptive Server Enterprise (CVE-2020-6317).
