The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned administrators to remediate a set of serious security vulnerabilities called ICMAD (Internet Communication Manager Advanced Desync) that affect SAP business applications using the Internet Communication Manager (ICM).
See also: Zimbra zero-day vulnerability allows email theft

CISA added that failure to patch these vulnerabilities exposes organizations with vulnerable servers to data theft, financial fraud risks, disruption of critical business processes, ransomware attacks , and cessation of all operations.
ICMAD bugs affect most SAP products
Yesterday, the researchers at Onapsis Research Labs who discovered and reported CVE-2022-22536, one of the three ICMAD flaws and the one assessed as a critical severity issue, urged SAP customers to fix them immediately (the other two are referenced as CVE-2022-22532 and CVE-2022-22533).
The SAP Product Security Response Team (PSRT) worked with Onapsis to create security patches to address these vulnerabilities and released them on February 8, during this month's Patch Tuesday.
See also: Hunting down the pwnkit vulnerability (CVE-2021-4034) on Linux
If a successful exploit occurs, the ICMAD flaws allow attackers to target users, business information and SAP processes and to steal credentials, trigger denials of service, execute remote code, and ultimately compromise any unpatched SAP applications.

So far no SAP client has been breached using the ICMAD exploits
SAP Security Response Director Vic Chung said they are currently not aware of any breaches of customer networks using exploits targeting these vulnerabilities and advised all affected organizations to apply the patches “as soon as possible.”
See also: Critical vulnerability in WordPress plugin affects thousands of sites
SAP customers can use this open source tool developed by Onapsis security researchers to help scan systems for ICMAD vulnerabilities.
Information source: bleepingcomputer.com
