The September 2022 SAP Security Patch Day addressed several high-priority vulnerabilities across the SAP ecosystem, including critical flaws in SAP GRC Access Control, BusinessObjects (BOBJ), SAP Business One, and SAP SuccessFactors. These patches resolve risks related to unauthorized access, privilege escalation, and information disclosure.
Executive Summary
The September 2022 security updates from SAP targeted critical vulnerabilities that could allow attackers to bypass security controls or gain elevated system privileges. A primary focus of this release was SAP GRC Access Control, where a vulnerability could enable unauthorized access to Firefighter sessions. Other significant patches addressed privilege escalation and information disclosure risks within SAP BusinessObjects Business Intelligence (BOBJ), SAP Business One, and SAP SuccessFactors. Organizations using these platforms are advised to review and apply the relevant security notes to mitigate potential exploitation. This summary outlines the key vulnerabilities addressed, including specific requirements for patch implementation, such as the authorization changes needed for GRC RFC users.
Key Takeaways
- Note 3237075 patches a high-priority vulnerability in SAP GRC Access Control involving Firefighter session security.
- SAP BusinessObjects (BOBJ) received patches for privilege escalation and information disclosure risks in the Central Management Server (CMS) and Central Management Console (CMC).
- High-risk privilege escalation vulnerabilities were identified and patched in both SAP Business One and SAP SuccessFactors.
- Note 2998510 was updated to clarify cross-platform OS exploitation risks for BOBJ authentication credentials.
What are the critical vulnerabilities in SAP GRC Access Control?
The primary vulnerability in SAP GRC Access Control, addressed by note 3237075, involves the potential for attackers to access Firefighter sessions even after they are closed in the Firefighter Logon Pad. Firefighter IDs are dedicated user identities with elevated privileges controlled through Emergency Access Management (EAM). To secure these sessions, the patch enables the detection of active sessions using SM04 and SM05 information. Implementing this correction requires the GRC RFC user to have authorization object SADMI_FCD with the value PADM. SAP notes that this implementation may cause a slight performance degradation due to the additional SM04 check during logon on the central system.
Which vulnerabilities affect SAP BusinessObjects (BOBJ)?
SAP BusinessObjects (BOBJ) received patches for two primary vulnerabilities:
- Note 3213507 resolves a privilege escalation and information disclosure vulnerability in the Business Intelligence (BOBJ) platform that could lead to the retrieval and modification of sensitive system data from the Central Management Server (CMS) and Monitoring DB.
- Note 3217303 patches a similar vulnerability specifically within the BOBJ Central Management Console (CMC).
- Additionally, note 2998510 was updated to confirm that sysmon is not the only OS application that can be exploited to compromise CMS authentication credentials, and that this risk affects BOBJ installations on both Linux/Unix and Windows.
Which other SAP solutions were impacted in September 2022?
Notes 3223392 and 3226411 address high-risk privilege escalation vulnerabilities in SAP Business One and SAP SuccessFactors, respectively. These vulnerabilities could be exploited by malicious actors to gain unauthorized system privileges, necessitating immediate attention from administrators managing these environments.
FAQ
What are Firefighter IDs in SAP GRC?
Firefighter IDs are dedicated user identities with elevated privileges in SAP GRC. They are activated only when required and are strictly controlled through the Emergency Access Management (EAM) framework to ensure accountability during emergency system changes.
Does the GRC patch affect system performance?
Yes, according to SAP, implementing note 3237075 will lead to a slight degradation in performance. This is due to the additional time required to perform the SM04 check during user logon on the central system.
What authorization is required for the GRC RFC user after patching?
To properly retrieve the SM05 data required for the new security check, the GRC RFC user must be granted authorization object SADMIFCD with the value PADM.