SAP Updates
3049Warning Date
Severity Level
Warning Number
Target Sector
15 January, 2020
● Medium
2020-798
All
Description:
SAP has released security updates to address multiple vulnerabilities in the following products:
- SAP Process Integration - Rest Adapter (SAP_XIAF), Versions: 7.31, 7.40, 7.50
- SAP NetWeaver Internet Communication Manager, Versions: -KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT , KRNL64NUC & KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KERNEL 7.21, 7.22, 7.49, 7.53
- RTCISM, Version: 100
- SAP Disclosure Management, Version: 10.1
- Automated Note Search Tool (SAP Basis), Versions: 7.0, 7.01,7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54
- SAP UI, Versions: 7.5, 7.51, 7.52, 7.53, 7.54, 2.0
- SAP Leasing, Versions: (SAP_Appl) 6.18, (EA_Appl) 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16 and 6.17
Threats:
Attacker could exploit these vulnerabilities by by doing the following:
- Cross-site scripting (XSS) attack.
- Denial of service (DoS) attack.
- Missing Authorization Check.
Best practice and Recommendations:
The CERT team encourages users to review SAP security advisory and apply the necessary updates:
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=533671771