Enhance Your SAP Security with Vicxer! Discover how to safeguard your SAP environment effectively.

SAP Security Patch Day – November 2024

  • Each month, SAP issues critical updates to fortify your systems against security threats.

  • On 12th of November 2024, SAP Security Patch Day saw the release of 8 new security notes, along with 2 updates to previously released Security Notes. 

  • This month’s release encompasses two (2) high-priority, six (6) medium-severity, and two (2) low-severity vulnerabilities that require attention from the SAP administrators and security team.

Inside Critical Web Dispatcher Vulnerability

Marked as ‘high priority’ (the second most severe rating in SAP’s playbook) the most important security note relesead this month addresses an important vulnerability in Web Dispatcher, the component that distributes incoming requests to the adequate SAP instances acting as a web load balancer and web request filter. 

In its advisory , SAP describes the security defect tracked as CVE-2024-47590 with a CVSS score of 8.8 as a cross-site scripting (XSS) vulnerability. However, deeper analysis reveals that this vulnerability can also be exploited as a Server-Side Request Forgery (SSRF) attack. 

Attack Vector Analysis 

The attack flow operates through a sophisticated dual-exploitation path: 

  1. An unauthenticated attacker creates a malicious link 

  2. When an authenticated administrator / user clicks the link, the input data is weaponized in two ways: 

A. Executes malicious content in the victim’s browser through XSS 

B. Performs server-side request forgery (SSRF), potentially leading to remote code execution on the server itself

Mitigation Strategies

SAP customers are strongly advised to apply the released security note (CVE-2024-47590) to address this critical issue. Alternative mitigation strategies include disabling the Admin UI, either through file deletion or profile parameter changes, or by completely removing the administrative role from all users – the latter being a recommended best practice when there is no specific requirement for administrative access

 

At Vicxer, we specialize in managing these critical security aspects for our clients. Our team of SAP security experts can handle the entire process, ensuring that your SAP systems remain secure and compliant, allowing you to focus on your core business operations without worrying about complex security vulnerabilities. 

Table of Contents

Discover more from Vicxer Inc | SAP Security

Subscribe now to keep reading and get access to the full archive.

Continue reading