SAP Security Patch Day – March 2022
Today, March 8th, 2022, is again Patch Day. SAP released security updates for the comprehensive SAP product portfolio. This month’s release counts 16 security patches, including the notes that have been updated.
SAP Security Patches - March 2022
During this March Patch Day, SAP is again releasing critical security patches. Among the 4 security updates with priority Hot News are 2 new advisories that deal with a remote code execution (RCE) vulnerability in SAP Work Manager and a missing authentication check in SAP Focused Run. The first update is vulnerability note 3123396, which was already published in February and allows an attacker to attack the SAP Web DISPATCHER and the SAP Content Server via http smuggling.
The second SAP security patch is Note 3131047. The note holds the summary of all Log4J related issues existing across all SAP products. It is advisable to regularly check this note and take all necessary precautions. Customers of the SecurityBridge platform have a key benefit, the patch management capabilities notify on missing security updates.
The SAP Fiori Launchpad has also received a security correction. The possibility of an attack via XSS is prevented with 3149805. Customers using SAP NetWeaver versions 754, 755, 756 should definitely install the fix, even though the severity is only rated as “High”.
As a side note, as of March the SAP Response Team changed the platform for their monthly publications. The platform shift was already announced in February with the following message “Going forward SAP Security Patch Day blogs will be published here: dam.sap.com”.
Summary by Severity
The March release contains a total of 16 patches for the following severities: