In October 2022, SAP released security patches addressing multiple critical vulnerabilities, including a URL redirection flaw in SAP Commerce Cloud (Note 3239152), a directory traversal vulnerability in SAP Manufacturing Execution (Note 3242933), an information disclosure risk in SAP BusinessObjects, and a denial-of-service vulnerability in SAP SQL Anywhere and SAP IQ.
Executive Summary
SAP’s October 2022 security updates addressed several high-risk and critical vulnerabilities across its product portfolio. The most significant update, Note 3239152, targeted a critical URL redirection vulnerability in SAP Commerce Cloud. This flaw could be exploited to manipulate URLs, redirect users to attacker-controlled logon pages, and subsequently facilitate credential theft and account hijacking.
Other notable patches included a directory traversal vulnerability in SAP Manufacturing Execution (Note 3242933) affecting the Work Instruction Viewer and Visual Test and Repair plugins. Additionally, an information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Note 3229132) exposed OS credentials in clear-text to administrators, while a buffer overflow vulnerability in SAP SQL Anywhere and SAP IQ (Note 3232021) presented a denial-of-service risk for database servers. Finally, SAP Visual Enterprise Viewer received patches for multiple high-risk vulnerabilities (Notes 3245929 and 3245928). Security teams are encouraged to review these notes and apply the necessary patches or workarounds to secure their SAP environments.
Key Takeaways
- SAP Commerce Cloud (Note 3239152) contains a critical URL redirection vulnerability allowing potential credential theft and account hijacking.
- SAP Manufacturing Execution (Note 3242933) is vulnerable to directory traversal, which could lead to unauthorized information disclosure.
- SAP BusinessObjects BI Platform (Note 3229132) has an information disclosure flaw that exposes OS credentials to administrators in clear-text.
- SAP SQL Anywhere and SAP IQ (Note 3232021) contain a buffer overflow vulnerability that can trigger a denial of service.
- SAP Visual Enterprise Viewer was updated to address multiple high-risk vulnerabilities (Notes 3245929 and 3245928).
Summary of October 2022 SAP Vulnerabilities
The following table summarizes the key SAP security notes released in October 2022.
| SAP Product | Security Note | Vulnerability Type |
|---|---|---|
| SAP Commerce Cloud | 3239152 | URL Redirection |
| SAP Manufacturing Execution | 3242933 | Directory Traversal |
| SAP BusinessObjects BI Platform | 3229132 | Information Disclosure |
| SAP SQL Anywhere / SAP IQ | 3232021 | Buffer Overflow |
| SAP Visual Enterprise Viewer | 3245929, 3245928 | Multiple High-Risk |
How can the SAP Commerce Cloud vulnerability be mitigated?
The critical URL redirection vulnerability in SAP Commerce Cloud (Note 3239152) is primarily mitigated by applying the provided software patches. If applying the patch is not immediately feasible, SAP details specific workarounds, such as removing the OAuth extension or implementing URL filtering through website redirects. However, organizations should be aware that these workarounds may have side effects, as the OAuth extension is required for integrations and modules like the SmartEdit Module and Assisted Service Module.
Frequently Asked Questions
What is the risk associated with Note 3239152 in SAP Commerce Cloud?
The vulnerability allows attackers to manipulate URLs to redirect users to unauthorized logon pages. This can be used to steal user credentials and hijack accounts.
Are there side effects to the suggested workarounds for SAP Commerce Cloud?
Yes. Removing the OAuth extension can impact functionality in modules such as the SmartEdit Module and the Assisted Service Module, as well as disrupt necessary system integrations.
What vulnerability affects SAP Manufacturing Execution?
Note 3242933 addresses a directory traversal vulnerability that could lead to information disclosure. The affected plugins are the Work Instruction Viewer (WI500) and the Visual Test and Repair (MODEL_VIEWER) tool.