SAP Security Patch Day – November 2022
Today, November 8th, 2022, SAP releases security fixes for their product portfolio for the penultimate time this year as part of November SAP Security Patch Day. SAP released 10 patches and updated 2 security notes from the previous Patch Day.
The following article describes how to use the Expert Search if you encounter a different number in SAP’s Support Launchpad’s Security Notes application.
The Expert Search shows 14 Security Patches between the recent SAP Security Patch Day and the November release.
Have you ever wondered why SAP Security Patch installation can’t be as easy as you’re used to with Windows Update? Join our webinar on November 10th at 3 pm CET. Senior Cybersecurity Analyst at Lonza will talk about his experiences with SAP Cybersecurity and our CTO Ivan Mans will show how SecurityBridge Patch Management can ease your life and significantly increase your system security.
SAP Security Patches November 2022
In this section, you will find a summary of the highlights, i.e., the SAP Security Notes for which we recommend quick action. At the same time, you should check all Security Notes for updates, including those already implemented. Unfortunately, it also happens that SAP experts update a previous fix outside the regular SAP Patch Day.
A large number of SAP customers may be affected by note 3256571, which addresses several vulnerabilities in SAP NetWeaver Application Server ABAP and ABAP Platform. The corrected SAP vulnerabilities are implemented with CVSS 8.7.
SAP Business Objects Intelligence Platform has received a fix with Hot News (CVSS 9.9). We recommend that you check the note with the number 3243924 for relevance. An authenticated attacker can inject malicious content with relatively low privileges. This could highly compromise the system’s confidentiality, integrity, and availability. The experts at SAP also publish workaround instructions. If you can’t install the patch mentioned in the note in the short term, we recommend you check the workaround and use it temporarily if necessary.
Customers using SAPUI5 but not one of the following library versions: 1.71.51, 1.84.29, 1.96.14, 1.102.8, 1.105.2 should take a closer look at note 3249990 [CVE-2021-20223]. The CVE number 2021 suggests that the vulnerability mentioned has existed for some time. Therefore, affected customers must ask themselves whether the vulnerability was exploited unnoticed. A particularly high risk exists for scenarios where the SAP Fiori /SAPUI5 user interface is exposed in untrusted networks.
Summary by Severity
The November release contains a total of 10 patches for the following severities: