Connect with us

Hi, what are you looking for?



Critical Access Control Vulnerability Patched in SAP Marketing

SAP this week announced the release of 10 new Security Notes as part of its September 2020 Security Patch Day, as well as updates for 6 previous Security Notes.

SAP this week announced the release of 10 new Security Notes as part of its September 2020 Security Patch Day, as well as updates for 6 previous Security Notes.

Two of the Security Notes are rated Hot News and address critical flaws in SAP Marketing – Mobile Channel Servlet (CVE-2020-6320 – improper access control) and NetWeaver (ABAP Server) and ABAP Platform (CVE-2020-6318 – code injection), which feature CVSS scores of 9.6 and 9.1, respectively.

Mobile Channel Servlet enables mobile campaigns in which push notifications are sent to Android and iOS devices via Google Firebase. The critical flaw addressed this week allows an authenticated attacker to access restricted functions.

“An exploit of the vulnerability enables an attacker to perform tasks related to contact and interaction data,” Onapsis, a firm that specializes in securing Oracle and SAP applications, explains.

The code injection flaw in NetWeaver would allow an attacker to take complete control of the application. Thus, the attacker could view, change, or delete data through code injected in memory and executed by the application, or could cause the application to terminate.

Additionally, SAP updated two other Hot News Security Notes, one addressing a missing authorization check in Solution Manager (CVE-2020-6207, CVSS score of 10), and another that deals with security updates for the Chromium browser in Business Client (CVSS score of 9.8).

Two other updated Security Notes deal with high-severity vulnerabilities, namely a code injection in NetWeaver (ABAP) and ABAP Platform (CVE-2020-6296), and a server-side request forgery in NetWeaver AS ABAP (CVE-2020-6275).

Advertisement. Scroll to continue reading.

“Three of the six HotNews and High Priority notes only contain more or less negligible update information that does not require customer action (compared to the initial/previous version of the notes). The two HotNews notes #2961991 and #2958563 only affect a small number of SAP customers (SAP Marketing, SAP NetWeaver AS ABAP on DB4 or Sybase). That gives enough time to check the status of all relevant security patches in your SAP systems,” Onapsis notes.

Five Security Notes released this week address medium-risk vulnerabilities in Bank Analyzer and S/4HANA Financial Products (CVE-2020-6311), Commerce (CVE-2020-6302), NetWeaver AS ABAP (CVE-2020-6324), NetWeaver AS Java (CVE-2020-6326), and Fiori (Launchpad) (CVE-2020-6283).

Two other medium-priority Security Notes address multiple vulnerabilities in BusinessObjects Business Intelligence Platform (CVE-2020-6325, CVE-2020-6312, and CVE-2020-6288) and 3D Visual Enterprise Viewer (38 CVEs).

This week, SAP released updates for two medium-priority bugs: one addressing cross-site scripting (XSS) vulnerabilities in the modified jQuery bundled with SAPUI5 (CVE-2020-11022, CVE-2020-11023) and another patching a server-side request forgery in NetWeaver AS JAVA (CVE-2020-6282).

SAP also announced a low-priority Security Note that patches an information disclosure vulnerability in Adaptive Server Enterprise (CVE-2020-6317).

Related: SAP Releases August 2020 Security Updates

Related: SAP Releases 10 Security Notes on July 2020 Patch Day

Related: Critical Vulnerability Patched in SAP Commerce

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

SecurityWeek’s Threat Detection and Incident Response Summit brings together security practitioners from around the world to share war stories on breaches, APT attacks and threat intelligence.


Securityweek’s CISO Forum will address issues and challenges that are top of mind for today’s security leaders and what the future looks like as chief defenders of the enterprise.


Expert Insights

Related Content


Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...


The latest Chrome update brings patches for eight vulnerabilities, including seven reported by external researchers.


Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.


Apple has released updates for macOS, iOS and Safari and they all include a WebKit patch for a zero-day vulnerability tracked as CVE-2023-23529.

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.