SAP Security Notes: April 2022 Summary

In April 2022, SAP released critical security updates addressing high-priority vulnerabilities, including the widespread Spring4Shell remote code execution flaw and serious code injection risks in SAP Manufacturing Integration and Intelligence (MII). These patches are essential for preventing unauthorized system access, privilege escalation, and service disruption.

What is the impact of the Spring4Shell vulnerability on SAP?

The Spring4Shell vulnerability (CVE-2022-22965) is a critical remote code execution (RCE) flaw affecting the open-source Java Spring Framework. SAP addressed this through central note 3170990 and several solution-specific notes, including 3189428, 3187290, 3189429, 3189635, and 3171258. These patches protect various SAP solutions, such as SAP HANA Extended Application Services, PowerDesigner Web, and SAP Commerce. Successful exploitation typically requires Apache Tomcat for serving applications built as a WAR file.

What other critical vulnerabilities were patched in April 2022?

Beyond Spring4Shell, SAP addressed significant risks in manufacturing and web communication components:

  • SAP Manufacturing Integration and Intelligence (MII): Notes 3022622 and 3158613 resolve a code injection vulnerability that could allow attackers to escalate privileges and execute OS-level commands. The fix blocks the saving of Java Server Pages (JSP) via the Self Service Composition Environment (SSCE).
  • SAP Web Dispatcher and Internet Communication Manager (ICM): Note 3111311 provides a fix for a high-priority Denial of Service (DoS) vulnerability. This issue was caused by a program error related to the icm/HTTP/file_access parameter, which manages static file access for URL prefixes.

Summary of April 2022 SAP Security Notes

SAP NoteComponentVulnerability TypeImpact
3170990 (Central)Spring FrameworkRemote Code ExecutionCritical (Spring4Shell)
3022622 / 3158613SAP MIICode InjectionPrivilege Escalation
3111311Web Dispatcher / ICMDenial of ServiceService Disruption

Frequently Asked Questions

What solutions are affected by the Spring4Shell vulnerability?

SAP solutions affected by Spring4Shell include SAP HANA Extended Application Services, PowerDesigner Web, and SAP Commerce. These were patched through notes 3189428, 3187290, 3189429, 3189635, and 3171258.

How does the SAP MII code injection vulnerability work?

The vulnerability in SAP Manufacturing Integration and Intelligence allowed attackers to save and execute Java Server Pages (JSP) via the Self Service Composition Environment (SSCE). This could be leveraged to escalate privileges and run arbitrary OS commands. The patch effectively blocks this vector.

What causes the Denial of Service vulnerability in the Web Dispatcher?

The DoS vulnerability is caused by a program error in the icm/HTTP/file_access parameter, which defines how the system handles static file access for specific URL prefixes. Note 3111311 resolves this error to prevent service disruption.

Share the Post: