SAP Update
3202Warning Date
Severity Level
Warning Number
Target Sector
9 October, 2019
● High
2019-497
All
Description:
SAP has released security update to address multiple vulnerabilities in the following products:
- SAP Landscape Management enterprise edition version: 3.0
- SAP NetWeaver Process Integration (AS2 Adapter) versions: :1.0 – 2.0
- SAP IQ version: 16.1
- SAP NetWeaver Process Integration (B2B Toolkit) versions: 1.0 – 2.0
- SAP SQL anywhere version: 17
- SAP Customer Relationship Management (Email Management) versions: S4CRM 100 -200 - BBPCRM 700 - 701- 702 - 712 - 713 – 714
- SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) versions: 420 – 430
- SAP Financial Consolidation versions:10.0 -10.1
- SAP Dynamic Tiering versions: 1.0 – 2.0
- SAP Kernel (RFC) versions: KRNL32NUC- KRNL32UC - KRNL64NUC 7.21- 7.21EXT- 7.22- 7.22EXT- KRNL64UC 7.21- 7.21EXT- 7.22- 7.22EXT- 7.49- 7.73- KERNEL 7.21- 7.49- 7.53- 7.73- 7.76
Threats:
Remote attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting attack (XSS)
- Denial of service attack (DoS).
- Information disclosure.
Best practice and Recommendations:
The CERT team encourages users to update the affected products and to review SAP security advisory: https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050