ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Intel, SAP, and Citrix release critical security updates

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-6284
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate fil

SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of the script content could result in complete compromise of system confidentiality, integrity and availability, leading to Stored Cross Site Scripting.

NVD description · AI analysis pending
9.02%
  • sap netweaver knowledge management
CVE-2020-6287
Missing Authentication (RECON) in SAP NetWeaver AS Java LM Configuration Wizard

CVE-2020-6287 is a missing authentication check (CWE-306) in the LM Configuration Wizard component of SAP NetWeaver Application Server Java versions 7.30, 7.31, 7.40 and 7.50. An unauthenticated remote attacker can reach the configuration interface over the network and execute critical configuration tasks without any credentials. This allows the attacker to create administrative users and take full control of the SAP Java system, compromising its confidentiality, integrity and availability. Any organization running SAP NetWeaver AS Java on the affected versions is exposed, especially instances where the LM Configuration Wizard is reachable from untrusted networks. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, carries a 94.7% EPSS probability of exploitation within 30 days, and news reports describe mission-critical SAP applications under active attack.

Do: Apply SAP's security updates for NetWeaver AS Java 7.30, 7.31, 7.40 and 7.50 per the vendor's instructions (patches were released in July 2020), prioritizing internet-facing systems given the CISA KEV listing. As an interim mitigation, restrict network access to or disable the LM Configuration Wizard on affected systems. Also audit the system for unexpected or newly created administrative users and review access logs for unauthenticated configuration requests.

10.095% KEV
  • SAP NetWeaver Application Server Java (LM Configuration Wizard) 7.30, 7.31, 7.40, 7.50
largetens of thousands of installations, with thousands directly internet-exposed
Full article307 words · extracted from helpnetsecurity.com · click to collapse

August 2020 Patch Tuesday was expectedly observed by Microsoft and Adobe, but many other software firms decided to push out security updates as well.

Intel SAP Citrix security updates august 2020

Apple released iCloud for Windows updates and Google pushed out fixes to Chrome. They were followed by Intel, SAP and Citrix.

Intel’s updates

It’s not unusual for Intel to take advantage of a Patch Tuesday. This time they released 18 advisories.

Among the fixed flaws are:

SAP’s updates

The German software corporation known for its enterprise software marked its Security Patch Day with the release of 15 security notes and an update to a previously released one (for the maximum severity RECON vulnerability – CVE-2020-6287 – in SAP NetWeaver AS JAVA).

Patches have been provided for flaws in a variety of offerings, including SAP ERP, SAP Business Objects Business Intelligence Platform, SAP S/4 HANA and various SAP NetWeaver components.

The most critical among the vulnerabilities fixed is CVE-2020-6284, a XSS vulnerability in the Knowledge Management component of NetWeaver AS.

Citrix’s updates

Citrix has released patches for a set of vulnerabilities in certain on-premises instances of Citrix Endpoint Management (aka XenMobile Server).

They are critical for customers running XenMobile Server 10.12 before RP2, XenMobile Server 10.11 before RP4, XenMobile Server 10.10 before RP6, and XenMobile Server before 10.9 RP5.

“We recommend these upgrades be made immediately. While there are no known exploits as of this writing, we do anticipate malicious actors will move quickly to exploit,” Citrix CISO Fermin Serna warned.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/08/12/intel-sap-citrix-security-updates-august-2020/