Your review has been sent successfully

SAP Update

3202
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

9 October, 2019

● High

2019-497

All

Description:

SAP has released security update to address multiple vulnerabilities in the following products:

  • SAP Landscape Management enterprise edition version: 3.0
  • SAP NetWeaver Process Integration (AS2 Adapter) versions: :1.0 – 2.0
  • SAP IQ version: 16.1
  • SAP NetWeaver Process Integration (B2B Toolkit) versions: 1.0 – 2.0
  • SAP SQL anywhere version: 17
  • SAP Customer Relationship Management (Email Management) versions: S4CRM 100 -200 - BBPCRM 700 - 701- 702 - 712 - 713 – 714
  • SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) versions: 420 – 430
  • SAP Financial Consolidation versions:10.0 -10.1
  • SAP Dynamic Tiering versions: 1.0 – 2.0
  • SAP Kernel (RFC) versions: KRNL32NUC- KRNL32UC - KRNL64NUC 7.21- 7.21EXT- 7.22- 7.22EXT- KRNL64UC 7.21- 7.21EXT- 7.22- 7.22EXT- 7.49- 7.73- KERNEL 7.21- 7.49- 7.53- 7.73- 7.76

Threats:

Remote attacker could exploit these vulnerabilities by doing the following:

  • Cross-site scripting attack (XSS)
  • Denial of service attack (DoS).
  • Information disclosure.

Best practice and Recommendations:

The CERT team encourages users to update the affected products and to review SAP security advisory: https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050

Last updated at 24 December, 2019

Rate the content

rate-icon
up icon