In July 2022, SAP released several high-priority security notes addressing critical vulnerabilities in SAP Business One, SAP BusinessObjects (BOBJ), and SAP Landscape Management. These patches resolve significant risks, including information disclosure, code injection, and authentication bypasses that could lead to system compromise or denial of service.
What were the primary security updates for SAP Business One?
July 2022 saw multiple high-priority patches for SAP Business One, focusing on integration security and system integrity:
- Information Disclosure (Note 3212997): Patches a vulnerability in the integration between Business One and SAP HANA. Exploitation could allow access to privileged account credentials through the HANA cockpit’s data volume. As a temporary workaround, customers can switch from XPath passwords to explicit passwords in the FTP Adapter.
- Authentication Bypass (Note 3157613): Addresses a missing authentication check in the License Service API, which could be leveraged by attackers to provoke a denial of service (DoS).
- Code Injection (Note 3191012): Resolves a vulnerability that allows threat actors to upload and execute malicious files. The patch implements blocks for file types found in the Microsoft block list.
Which other SAP components were affected in July 2022?
Beyond SAP Business One, critical security notes were released for other core SAP platforms:
- SAP BusinessObjects (BOBJ): Note 3221288 patches a vulnerability that can lead to the leakage of sensitive token information and access credentials.
- SAP Landscape Management: Note 3213141 resolves a similar vulnerability involving the potential leakage of access credentials.
Summary of July 2022 SAP Security Notes
| SAP Note | Component | Vulnerability Type | Risk Level |
|---|---|---|---|
| 3212997 | SAP Business One / HANA | Information Disclosure | High |
| 3157613 | Business One License Service | Authentication Bypass | High |
| 3191012 | SAP Business One | Code Injection | High |
| 3221288 | SAP BOBJ | Credential Leakage | High |
| 3213141 | SAP Landscape Management | Credential Leakage | High |
Frequently Asked Questions
How can I mitigate the Business One/HANA information disclosure risk?
If you cannot immediately apply the patch from note 3212997, you can use a temporary workaround by switching from XPath passwords to explicit passwords within the FTP Adapter.
What is the risk of the code injection vulnerability in Business One?
The vulnerability resolved by note 3191012 allows threat actors to upload and execute malicious executable files (such as .exe or .bat). The patch mitigates this by blocking file types identified in the Microsoft block list.
Why are the July 2022 updates considered high priority?
These updates are classified as high priority because they address vulnerabilities that could lead to full system compromise, credential theft, or service disruption. Specifically, the ability for an unauthenticated attacker to inject code or access privileged credentials poses a severe risk to SAP environments.