 |
 |
 |
 |
|
This patch updates close 13 public vulnerabilities in SAP products. 3 of those vulnerabilities were founded by DSecRG researchers Alexander Polyakov and Dmitriy Chastuhin. SAP traditionally sent acknowledgements for founded vulnerabilities to security researchers from DSecRG on their acknowledgement page.
The most critical one is Buffer Overflow in SAP Frontend application that can be exploited to gain unauthorized access to all workstations that use SAP Frontend (SAP GUI for Windows). This vulnerability has priority 1 according to SAP metrics. Others are cross-site scripting vulnerabilities in SAP NetWeaver.
It is highly recommended to patch all those issues to prevent business risks.
Solutions for those issues are available in sap notes:
1504547,1443367,1490335
Advisories for those issues with technical details will be available after 3 month on erpscan.com and also on DSecRG.com site.
|
|
 |
 |
 |
 |
|
|
|