HomeSecuritySAP: Security updates to address important vulnerabilities

SAP: Security updates to address critical vulnerabilities

In an effort to mitigate the risks associated with 19 vulnerabilities, five of which have been rated critical, SAP has released a series of security updates. These should be applied immediately by administrators for maximum protection, as soon as possible.

See also: Fortinet warns of new critical vulnerability

SAP

This month, a number of issues affecting multiple products were fixed . However, the most pressing and critical bugs were in the SAP Business Objects (CMC) business intelligence platform as well as SAP NetWeaver .

More specifically, this round of updates addresses the following five vulnerabilities:

  • CVE-2023-25616: An attacker could exploit this critical code injection vulnerability (CVSS v3:9.9) in SAP Business Intelligence Platform, giving them access to resources normally available only to privileged users. Versions 420 and 430 are both vulnerable to the bug.
  • CVE-2023-23857: A critical (CVSS v3:9.8) information disclosure, data manipulation, and denial of service vulnerability has been identified in SAP NetWeaver AS for Java version 7.50. This flaw could allow an unauthenticated attacker to perform unauthorized operations by connecting to an accessible interface and using the directory API for services.
  • CVE-2023-27269: Critical directory traversal vulnerability (CVSS v3:9.6) affecting SAP NetWeaver Application Server for ABAP. The flaw allows a non-administrator user to overwrite system files. It affects versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, and 791.

See also: TPM 2.0 vulnerabilities put cryptographic keys at risk!

updates
  • CVE-2023-27500: Critical Severity List Traversal (CVSS v3:9.6) in SAP NetWeaver AS for ABAP. An attacker can exploit the SAPRSBRO flaw to overwrite system files, causing damage to the vulnerable endpoint. Impacts versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757.
  • CVE-2023-25617: Critical (CVSS v3:9.0) command execution vulnerability in SAP Business Objects Business Intelligence Platform, versions 420 and 430. The flaw allows a remote attacker to execute arbitrary commands on the operating system using BI Launchpad, Central Management Console, or a custom application based on the public Java SDK, under certain conditions.

In addition to the above, SAP's monthly security patch fixed four high-severity flaws and ten medium-severity vulnerabilities.

Security vulnerabilities in SAP's product offerings make them extremely attractive to malicious actors, as they are widely used by large companies around the world – providing direct access to high-value systems.

Holding 24% of the global ERP market share, SAP dominates with 425,000 customers in 180 countries. Boasting an impressive 90% usage rate among the Forbes Global 2000, its ERP, SCM, PLM and CRM products have become essential.

See also: Aruba Networks patches six critical vulnerabilities in ArubaOS

In February 2022, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged administrators to patch a series of critical vulnerabilities affecting SAP business applications to prevent potential data theft, ransomware attacks, and disruption of key processes and operations. In April 2021, malicious actors exploited known vulnerabilities in unpatched SAP systems as a means of penetrating corporate networks.

As a leading software provider, SAP plays a critical role in shaping the evolution of business processes around the world. With innovative solutions, a global presence, and a Fortune 500 customer base, SAP continues to define the landscape of business application software.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS