ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Patch Day for August includes the most critical Note released by SAP in 2019

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0344
Unauthenticated Deserialization RCE in SAP Commerce Cloud (virtualjdbc)

SAP Commerce Cloud releases 6.4, 6.5, 6.6, 6.7, 1808, 1811 and 1905 use unsafe deserialization of untrusted data in the virtualjdbc extension, letting attackers who can reach that component over the network inject and execute arbitrary code. No authentication or user interaction is required, which is reflected in the critical 9.8 CVSS 3.1 score. Successful exploitation yields code execution under the 'Hybris' user account on the target machine, enough to compromise the commerce platform and pivot further into the environment. Any organization running one of the listed SAP Commerce versions with the virtualjdbc extension deployed is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-30, confirming exploitation in the wild, although no public proof-of-concept is known.

Do: Upgrade affected SAP Commerce releases (6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905) to the patched patch levels per SAP's security advisory for CVE-2019-0344, or move to a current supported release. If patching is delayed, restrict network access to the virtualjdbc extension or remove it if unused, and verify whether it is exposed to the internet. Given the KEV listing, review logs for suspicious requests to the virtualjdbc endpoint and unexpected processes running as the 'Hybris' user; federal agencies must apply vendor mitigations or discontinue use of the product.

9.87% KEV
  • SAP Commerce Cloud (virtualjdbc extension) 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905
moderatelikely in the low thousands of installations; internet-exposed subset unknown
CVE-2019-0345
A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.4

A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication credentials for its own SAP Management console, resulting in Server-Side Request Forgery.

NVD description · AI analysis pending
9.82%
  • sap netweaver application server java
CVE-2019-0351
A remote code execution vulnerability exists in the SAP NetWeaver UDDI Server (Services Registry), versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50.

A remote code execution vulnerability exists in the SAP NetWeaver UDDI Server (Services Registry), versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50. Because of this, an attacker can exploit Services Registry potentially enabling them to take complete control of the product, including viewing, changing, or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the product to terminate.

NVD description · AI analysis pending
8.83%
  • sap netweaver
Full article478 words · extracted from securityaffairs.com · click to collapse

SAP Patches Highest Number of Critical Flaws Since 2014

SAP released Security Patch Day updates for August 2019 that address three critical vulnerabilities in the company’s products.

SAP has released the Security Patch Day for August, this month the company addresses several flaws, including three critical vulnerabilities (Hot News), the highest number of critical flaws since 2014. The August’s Patch Day includes a total of 23 SAP Security Notes.

“On 13th of August 2019, SAP Security Patch Day saw the release of 12 Security Notes. There is 1 update to previously released Patch Day Security Notes.” reads the advisory published by SAP.

Experts from Onapsis noticed that this SAP Security Patch Day has the highest number of critical notes in 2019, tree HotNews and two High Priority Notes released, plus one re-released HotNews note

SAP released 12 Security Notes to address flaws in NetWeaver, Business Client, Commerce Cloud, HANA, ABAP, BusinessObjects, Enable Now, and Gateway products.

One of the Hot News is an update to a Security Note initially released in April 2018 for Business Client, the other Hot News are:

  • A remote code execution flaw in the NetWeaver UDDI Server tracked as CVE-2019-0351. This issue has a CVSS score of 9,9, the highest one assigned this year, it could be exploited by an attacker to inject code into working memory.
  • Some code injection vulnerabilities in Commerce Cloud tracked as CVE-2019-0344.
  • A server-side request forgery (SSRF) vulnerability in the NetWeaver Application Server for Java tracked as CVE-2019-0345 that could be exploited by an attacker to gain admin access to the Management Console for SAP Java systems. The issue was discovered by Onapsis researchers.

“For the first time this year, SAP has published a Security Note with a CVSS of 9.9. This top scorer, SAP Security Note #2800779, is titled “Remote Code Execution (RCE) in SAP Netweaver UDDI Server (Services Registry)” and warns that attackers can take advantage of a buffer overflow vulnerability to inject code into the working memory.” reads the analysis published by Onapsis.”Because of the low complexity of this attack scenario in conjunction with the wide range of possible damages (e.g. information disclosure, data manipulation and destruction) up to the complete control of the product, this Note is considered as the most critical one to be released by SAP in 2019. “

SAP Security Patch Day for August 2019, also addressed two “high severity ” issues, a DoS vulnerability in SAP HANA and a missing authorization check issue in a SAP kernel package.

Security Patch Day August 2019

“Considering the number of four HotNews and two High Priority Security Notes and taking into account the wide range of attack vectors exploitable in various SAP platforms, the August Patch Day demonstrates impressively the importance of keeping your systems up to date,” concludes Onapsis.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – SAP Patch Day, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/89881/breaking-news/security-patch-day-august-2019.html