With the vast amount of sensitive information held in SAP, it is crucial to be aware of vulnerabilities and address them promptly. Monthly, SAP releases security updates and patches for their software products, known as SAP Notes, to tackle these vulnerabilities.
Understanding these updates is essential to maintaining the security and integrity of your SAP environment. Let’s dive into the latest SAP vulnerabilities and learn how to handle them effectively.
This month's security notes overview
Periodically, our Vicxer experts analyze the latest SAP Security Notes, and explore solutions to address them.
For July 2024, 16 new and 2 updated Security Notes were revealed.
Among these, two are high-priority notes with CVSS scores ranging from 7.2 to 7.7. The Common Vulnerability Scoring System (CVSS) score (v3) helps to measure the severity of security vulnerabilities, ranges from 0 to 10, with higher scores indicating more critical issues.
In this blog, we will focus on these high-priority notes, explaining their importance and how to address them.
The remaining Security Notes addresses medium and low-severity issues across various SAP products, including vulnerabilities like information disclosure, cross-site scripting (XSS), and authorization flaws.
These patches aim to mitigate potential risks to SAP deployments.
High-Priority Security Notes
This is the most critical note of the month, with a CVSS score of 7.7, addressing a “Missing Authorization Check in SAP PDCE.” But what does it mean? This vulnerability might allow authorized users of SAP Product Design Cost Estimating (PDCE) to escalate their privileges and access sensitive information due to a missing authorization check.
The recommended patch disables the vulnerable function and enforces necessary access restrictions to prevent unauthorized access. As there are no temporary solutions to mitigate this issue, it’s crucial to implement the suggested support package or follow the remediation instructions in the security note to remediate this vulnerability.
This note received a CVSS score of 7.2 and addresses “Improper Authorization Checks on Early Login Composable Storefront B2B Sites of SAP Commerce.” But what does it mean? Imagine you are a merchant that owns a site on SAP Commerce. An attacker can generate a pre-registered user and misuse the forgotten password functionality, to access your Composable Storefront B2B site without approval. This could compromise sensitive business data.
SAP Commerce Cloud fixes this by not sending password reset emails if the customer requesting a reset was not approved beforehand. Temporarily, SAP recommends disabling registration on isolated sites with Early Login enabled or, for all non-isolated sites if they have Early Login enabled.
Our Technical Recommendation
Like any system, SAP is not free from vulnerabilities, but with the right assistance, business can protect their assets against the ever-evolving cyber threats. Don’t wait until it’s too late! At Vicxer, we want to assist you with some proactive steps, to protect your SAP data today:
- Staying informed about the latest SAP vulnerabilities: Keep up with the latest SAP vulnerabilities by subscribing to our free newsletter. You’ll receive timely updates and recommendations to address new security issues.
- Adopt a Patch Management Strategy: Implementing patches promptly is crucial, and new patches can be challenging to incorporate. Vicxer’s dedicated team can assist you in applying updates efficiently and effectively, providing immediate and cost-effective responses to security concerns.
- Monitor and Respond: Continuous monitoring is essential for detecting potential threats and quickly reacting to them. Vicxer offers a premium automatic solution to monitor, detect and response to active exploitation / attacks.
- Assess and Prioritize: Regularly assess your SAP system to identify and prioritize vulnerabilities. Our approach focuses on understanding the risks and recommending the necessary fixes based on their impact on your critical assets, enabling you to allocate resources where they are most needed.