CERT-In Advisory
CIAD-2023-0037
Multiple Vulnerabilities in SAP Products
Original Issue Date: October 12, 2023
Severity Rating: Medium
Software Affected
- SAP Business Client, Versions -6.5,7.0,7.70
- SAP BusinessObjects Web Intelligence
- SAP PowerDesigner Client
- SAP NetWeaverAS Java
- S/4HANA (Manage Withholding Tax Items)
- SAP NetWeaver AS for Java (Log Viewer)
- SAP Business One (B1i)
- SAP S/4HANA Core
Overview
Multiple vulnerabilities have been reported in SAP Products which could allow an attacker to escalate privileges, execute arbitrary code, disclose sensitive information, perform SSRF attacks, inject system logs, perform Cross site scripting (XSS) attacks, redirect users to arbitrary URL and bypass security restrictions on the targeted system.
Description
Multiple vulnerabilities have been reported in SAP products; details of which are provided below:

Solution
Apply appropriate fixes as mentioned in SAP Security Advisory:
https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10
Vendor Information
SAP
https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10
References
SAP
https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10
CVE Name
CVE-2023-42474
CVE-2023-40310
CVE-2023-42477
CVE-2023-42473
CVE-2023-31405
CVE-2023-31405
CVE-2023-41365
CVE-2023-42475
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|