SAP Patch Day: October 2024
High Priority Patches for SAP Enterprise Project Connection and SAP BusinessObjects
Highlights of October SAP Security Notes analysis include:
- October Summary—12 new and updated SAP security patches released, including one HotNews Note and three High Priority Notes
- News from Log4j and Spring framework—Vulnerabilities in the well-known open-source libraries require High Priority patch for SAP Enterprise Project Connection
- Updates on six SAP Security Notes—Patches released for additional software component versions
SAP has released twelve SAP Security Notes on its October Patch Day (including the notes that were released or updated since last Patch Tuesday) This includes one HotNews Note and three High Priority Notes.
The HotNews Security Note #3479478, tagged with a CVSS score of 9.8, was initially released in August 2024 and patches a Missing Authentication Check vulnerability in SAP BusinessObjects Business Intelligence Platform. The note has now been updated and includes an additional patch for SAP customers who are on SBOP BI PLATFORM SERVERS 4.2 SP009.
Additional patches are also provided for a Missing Authorization Check vulnerability in SAP Product Design Cost Estimating (PDCE) that was initially fixed in July 2024 in collaboration with the Onapsis Research Labs. High Priority Note #3483344, tagged with a CVSS score of 7.7 now includes patches for the additional software components SEM-BW 600 to SEM-BW 748.
The New High Priority Notes in Detail
The Spring Framework and Log4j open-source libraries are back again on SAP Patch Day.
SAP Security Note #3523541, tagged with a CVSS score of 8.0, patches multiple vulnerabilities in SAP Enterprise Project Connection by upgrading the relevant library versions. The vulnerabilities are tracked under CVE-2024-22259, CVE-2024-38809, CVE-2024-38808, CVE-2022-23302.
SAP Security Note #3478615 affects all SAP BusinessObjects Business Intelligence Platform customers and patches an Insecure File Operations vulnerability, tagged with a CVSS score of 7.7. If not patched, authenticated users can send specially crafted requests to the Web Intelligence Reporting Server to download any file from the machine hosting the service.
Summary & Conclusions
With only twelve SAP Security Notes, including only six new notes, SAP’s October Patch Day is a calm Patch Day. We recommend checking the updated SAP Security Notes in detail since most of them were extended by patches for additional software component versions.
SAP Note | Type | Description | Priority | CVSS |
3479478 | Update | [CVE-2024-41730] Missing Authentication check in SAP BusinessObjects Business Intelligence Platform BI-BIP-INV | HotNews | 9.8 |
3523541 | New | [CVE-2022-23302] Multiple vulnerabilities in SAP Enterprise Project Connection CA-EPC | High | 8.0 |
3478615 | New | [CVE-2024-37179] Insecure File Operations vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) BI-RA-WBI-BE | High | 7.7 |
3483344 | Update | [CVE-2024-39592] Missing Authorization check in SAP PDCE FIN-BA | High | 7.7 |
3477359 | Update | [CVE-2024-45283] Information disclosure vulnerability in SAP NetWeaver AS for Java (Destination Service) BC-JAS-SEC-DST | Medium | 6.0 |
3507545 | New | [CVE-2024-45278] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice CEC-SCC-CDM-BO-APP | Medium | 5.4 |
3503462 | New | [CVE-2024-47594] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC) EP-KM-ADM-CFG | Medium | 5.4 |
3520100 | New | [CVE-2024-45277] Prototype Pollution vulnerability in SAP HANA Client HAN-DB-CLI | Medium | 4.3 |
3251893 | New | [CVE-2024-45282] HTTP Verb Tampering in SAP S/4 HANA(Manage Bank Statements) FI-FIO-AR | Medium | 4.3 |
3481588 | Update | [CVE-2024-41729] Information Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer) BW-BEX-ET-WB-7X | Medium | 4.3 |
3479293 | Update | [CVE-2024-42373] Missing Authorization Check in SAP Student Life Cycle Management (SLcM) IS-HER-CM-AD | Medium | 4.3 |
3454858 | Update | [CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform BC-SRV-DX-DXW | Medium | 4.1 |
As always, the Onapsis Research Labs are already updating The Onapsis Platform to incorporate the newly published vulnerabilities into the product so that our customers can protect their businesses.
For more information about the latest SAP security issues and our continuous efforts to share knowledge with the security community, subscribe to our Defenders Digest Newsletter.