ZeroHour
Security Affairspublished ()ingested @securityaffairs

SAP October 2019 Security Patch Day fixes 2 critical flaws

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0368
SAP Customer Relationship Management (Email Management), versions:

SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client resulting in Cross-Site Scripting vulnerability.

NVD description · AI analysis pending
5.4<1%
  • sap customer relationship management bbpcrm
  • sap customer relationship management s4crm
CVE-2019-0374
+4 in the same advisory: …0375 …0376 …0377 …0378
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the chart title resulting in reflected Cross-Site Scripting

NVD description · AI analysis pending
5.4<1%
  • sap businessobjects business intelligence platform
CVE-2019-0379
SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is ch

SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authentication Check

NVD description · AI analysis pending
5.3<1%
  • sap process integration
CVE-2019-0380
Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the app

Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure.

NVD description · AI analysis pending
4.9<1%
  • sap landscape management
CVE-2019-0381
A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the in

A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user.

NVD description · AI analysis pending
5.5<1%
  • sap dynamic tier
  • sap sap iq
  • sap sql anywhere
Full article521 words · extracted from securityaffairs.com · click to collapse

SAP addressed two critical vulnerabilities (Hot News) as part of the October 2019 Security Patch Day.

SAP has released its October 2019 Security Patch Day updates that also address two critical vulnerabilities (Hot News) with CVSS scores of 9.3 and 9.1.

The October 2019 Security Patch Day also includes a High Priority Note addressing Binary Planting vulnerability.

“With only nine new and one updated Security Note, SAP has published an unusually low number of Security Notes for October 2019.” reads the analysis published by security firm Onapsis. “This is the lowest number of newly published notes in the past five years. Nevertheless, with 2 HotNews Notes and one High Priority Note, this Patch Day deserves special attention as an attacker needs only one vulnerability for a successful attack.”

The most severe SAP Security Note is #2826015, a Missing Authentication Check in AS2 Adapter of B2B Add-On for SAP NetWeaver Process Integration. The vulnerability, tracked as CVE-2019-0379, could be exploited by remote attackers to steal or manipulate sensitive data, it could also provide attackers with access to administrative and other privileged functionality.

“The adapter specifies a comprehensive set of data security features, specifically data confidentiality and data authenticity, which are aimed at the B2B commerce environment. The configuration of the AS2 adapter allows two different security providers.” reads the analysis published by Onapsis. “Depending on the selected provider, a Missing Authentication vulnerability exists that can lead to sensitive data theft or data manipulation as well as to access to administrative and other privileged functionalities.”

The vulnerability received a CVSS score of 9.3.

The second Hot News (SAP Security Note #2828682) addresses a flaw tracked as CVE-2019-0380, it is an information disclosure flaw in SAP Landscape Management enterprise edition. the flaw affects version 3.0 and received a CVSS score of 9.1.

“SAP Security Note #2828682 talks about a risk of information disclosure if these custom parameters fulfill specific conditions. SAP describes the overall conditions for the existence of the vulnerability as “uncommon”.  “

The vulnerability is related to the custom parameters that can be added by users to providers assigned to custom operations.

SAP also addressed a Binary Planting vulnerability in several SAP software products, including Anywhere, SAP IQ and SAP Dynamic Tiering. The flaw tracked as CVE-2019-0381 resides in the file search algorithm of the affected products, it received a CVSS score of 7.8.

“The algorithm searches too many directories, even if they are out of the application scope.” Onapsis explains. “Possible impacts are path traversals and directory climbing, enabling an attacker to read, overwrite, delete, and expose arbitrary files of the system. This can also lead to DLL hijacking as well as to privilege elevation.”

SAP also addressed multiple Cross-Site Scripting (XSS) vulnerabilities in its products, rated as medium, including one in Customer Relationship Management (CVE-2019-0368), and multiple issues in the SAP BusinessObjects Business Intelligence Platform (CVE-2019-0374, CVE-2019-0375, CVE-2019-0376, CVE-2019-0377, and CVE-2019-0378),

The full list of the addressed issues in SAP Security Patch Day – October 2019 is available here.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – SAP, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/92335/security/sap-october-2019-security-patch-day.html