Description

On Tuesday, SAP announced the release of 14 new and three updated security notes as part of its May 2024 Security Patch Day. Among these, two new and one updated security notes are rated as 'hot news', indicating critical flaws in Business Client, CX Commerce, and NetWeaver Application Server ABAP and ABAP Platform. The first of these resolves two vulnerabilities in Customer Experience (CX) Commerce, both involving third-party libraries. The most severe, CVE-2019-17495, is a CSS injection issue in Swagger UI with a CVSS score of 9.8, allowing CSS-based input field value exfiltration using the Relative Path Overwrite technique. Additionally, CVE-2022-36364, a remote code execution flaw in the Apache Calcite Avatica library (CVSS score of 8.8), was also patched. The second 'hot news' note addresses CVE-2024-33006, a file upload vulnerability in NetWeaver (CVSS score of 9.6) caused by missing signature checks for two content repositories. This flaw allows unauthenticated attackers to upload malicious files to the server, potentially compromising the entire system. Furthermore, the updated 'hot news' note includes the latest security updates for the Chromium-based browser in SAP Business Client, addressing 23 vulnerabilities, including three of high severity. SAP also released patches for a high-severity cross-site scripting (XSS) vulnerability in BusinessObjects Business Intelligence Platform, caused by insufficient sanitization of user input. The remaining 13 security notes resolve medium- and low-severity issues across various SAP products, including Enable Now Manager, NetWeaver, S/4HANA, My Travel Requests, and others. SAP customers are advised to apply these security updates promptly, as attackers have historically exploited patched security defects in SAP products.