Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

SAP Releases August 2020 Security Updates

SAP this week announced the release of 15 new Security Notes as part of the August 2020 SAP Security Patch Day, including some that address serious vulnerabilities in NetWeaver.

SAP this week announced the release of 15 new Security Notes as part of the August 2020 SAP Security Patch Day, including some that address serious vulnerabilities in NetWeaver.

The most important of these is a cross-site scripting (XSS) flaw in the Knowledge Management component of NetWeaver. Tracked as CVE-2020-6284 and featuring Hot News priority, the issue has a CVSS score of 9.

A default component of all SAP Enterprise Portal installations, Knowledge Management allows users to manage data sources in multiple formats, to create and modify content and folders, as well as upload files.

The upload function, ERP cyber-security provider Onapsis reveals, could be exploited to upload malicious HTML files containing JavaScript code, to perform a stored XSS attack. The issue was related to an inefficient filtering mechanism meant to prevent the upload of files injected with executable code.

Successful exploitation of the vulnerability requires for a user with administrative privileges to access the malicious file, which lowers the CVSS score to 9 — otherwise it would have been 9.9.

Another Hot News Security Note released on this Security Patch Day is an update for a July 2020 Security Note that addresses a critical bug (CVSS score 10) in NetWeaver AS JAVA (LM Configuration Wizard) that is tracked as CVE-2020-6287 and which is also referred to as RECON (Remotely Exploitable Code On NetWeaver).

On the August 2020 Security Patch Day, SAP also released three High Priority Security Notes addressing vulnerabilities in NetWeaver: CVE-2020-6296 (CVSS score 8.3) – code injection in NetWeaver (ABAP) and ABAP Platform; CVE-2020-6309 (CVSS score 7.5) – missing authentication in NetWeaver AS JAVA; and CVE-2020-6293 (CVSS score 7.3) – unrestricted file upload in NetWeaver (Knowledge Management).

According to Onapsis, if a patch for the Hot News flaw in Knowledge Management is not applied, CVE-2020-6293 – which allows an attacker to create, modify, or delete files in the Knowledge Management component – can be exploited without authentication, which essentially increases its CVSS score to 9.6, making it a critical flaw.

Advertisement. Scroll to continue reading.

SAP also released two High Priority Security Notes to patch missing authentication checks, one in the BusinessObjects Business Intelligence Platform – CVE-2020-6294 (CVSS score 8.5) – and another in Banking Services (Generic Market Data) – CVE-2020-6298 (CVSS score 8.3) – and another to resolve an information disclosure flaw in Adaptive Server Enterprise – CVE-2020-6295 (CVSS score 7).

Exploitation of some of these bugs could lead to denial of service, the leakage of mouse and keyboard activities and the ability to record screenshots, reading protected Business Partner Generic Market Data (GMD), or reading information in the installation log files.

All of the remaining Security Notes released on the August 2020 Security Patch Day address Medium Priority bugs, including XSS vulnerabilities in SAP Commerce, modified jQuery bundled with SAPUI5, and Business Objects Business Intelligence Platform (Central Management Console); information disclosure in Data Intelligence, and NetWeaver (ABAP Server) and ABAP Platform; and missing authorization checks in ERP (HCM Travel Management) and S/4 HANA (Fiori UI for General Ledger Accounting).

Related: SAP Releases 10 Security Notes on July 2020 Patch Day

Related: Critical Vulnerability Patched in SAP Commerce

Related: Open Source Tool Checks SAP Systems for RECON Attack IOCs

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.