ZeroHour
Security Affairspublished ()ingested @securityaffairs

SAP fixed critical SSRF flaw in NetWeaver

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-47578
Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application.

Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. On successful exploitation, the attacker can read or modify any file and/or make the entire system unavailable.

NVD description · AI analysis pending
9.1<1%
CVE-2024-47579
An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server.

An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the attacker to read any file on the server with no effect on integrity or availability

NVD description · AI analysis pending
6.8<1%
CVE-2024-47580
An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment.

An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can read any file on the server with no effect on integrity or availability.

NVD description · AI analysis pending
6.8<1%
CVE-2024-47590
An unauthenticated attacker can create a malicious link which they can make publicly available.

An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS) or transmitted to another server (SSRF) gives the attacker the ability to execute arbitrary code on the server fully compromising confidentiality, integrity and availability.

NVD description · AI analysis pending
8.8<1%
CVE-2024-54198
In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destin

In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote service, potentially resulting in a significant impact on the confidentiality, integrity, and availability of the application.

NVD description · AI analysis pending
8.5<1%
Full article343 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 10, 2024

SAP has issued patches for 16 vulnerabilities, including a critical SSRF flaw in NetWeaver’s Adobe Document Services.

SAP addressed 16 vulnerabilities as part of its December 2024 Security Patch Day. The company released nine new and four updated security notes.

The most severe of these vulnerabilities is a critical issue, tracked as CVE-2024-47578 (CVSS score of 9.1), in the Adobe Document Service component of NetWeaver. An attacker with administrative privileges can exploit the vulnerability to send a crafted request from a vulnerable web application. Successful exploitation can allow attackers to read or modify any file and/or make the entire system unavailable.

The vulnerability impacts versions ADSSSAP 7.50.

“Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability.” reads the advisory. “On successful exploitation, the attacker can read or modify any file and/or make the entire system unavailable.”

The company also addressed other two vulnerabilities, tracked as  CVE-2024-47579 and CVE-2024-47580, as part of the same security notes that was labeled as ‘hot news’.

Bot vulnerabilities are medium-severity issues that could be exploited by an attacker with administrative access to read files on the server.

“These vulnerabilities, tracked as CVE-2024-47578, CVE-2024-47579, and CVE-2024-47580, collectively expose organizations to potential server-side request forgery (SSRF), unauthorized file access, and information disclosure.” reads the analysis published by Onapsis.

SAP also addressed a Cross-Site Scripting (XSS) vulnerability (CVSS score of 8.8), tracked as CVE-2024-47590, in Web Dispatcher.

The company fixed an Information Disclosure vulnerability through Remote Function Call (RFC), tracked as CVE-2024-54198 (CVSS score of 8.5) in SAP NetWeaver Application Server ABAP

The company is not aware of attacks in the wild exploiting one of the issues addressed with the release of December 2024 Security Patch Day.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SAP)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/171839/security/sap-fixed-critical-ssrf-flaw-netweaver.html