Each month, SAP unveil critical updates known as “SAP Security Notes”.
On December 10th, 2024, SAP released 10 new security notes and 3 updates to previously released notes, reflecting a significant increase in critical vulnerabilities compared to the November release.
This month’s patches address vulnerabilities across multiple severity levels, with a particular focus on core SAP components.
Vulnerability overview
Here’s a detail overview of what’s included:
1 Hot News vulnerability (CVSS 9.1): Multiple vulnerabilities in Adobe Document Services that could allow system compromise.
4 High Priority vulnerabilities (CVSS 7.2-8.8): Including a critical RFC vulnerability enabling credential exposure, cross-site scripting in Web Dispatcher, and server-side request forgery issues.
5 Medium Priority vulnerabilities (CVSS 4.3-5.3): Comprising XML entity expansion, information disclosure, and missing authorization checks in various components.
2 Low Priority vulnerabilities (CVSS 2.7-3.3): Addressing DLL hijacking and information disclosure in Product Lifecycle Costing and Commerce Cloud.
Main Affected SAP Components
The most critical vulnerabilities impact the following core SAP components:
- SAP NetWeaver AS JAVA (Adobe Document Services)
- SAP Web Dispatcher
- SAP NetWeaver AS ABAP
- SAP BusinessObjects BI Platform
- SAP Commerce Cloud
The Bottom Line
- December 2024 SAP Security Patch Day underscores the critical need of organizations to pay attention to the overall SAP landscape, including SAP assets that sometimes might be underestimated
- At Vicxer, our team of SAP security specialists can help organizations navigate these critical updates, handle the complete patching process.
- Vicxer’s SAP Security Platform allows you to handle the complete cyber-security cycle, from the discovery of the vulnerabilities in your SAP landscape, to the remediation process and 24/7 security monitoring.