Skip to main content

SAP Releases February 2022 Security Updates

SAP partner Onapsis, with cooperation from SAP, has released a threat report about critical vulnerabilities in ICM.  The regularly scheduled security updates for multiple SAP products also include updates for products affected by Log4Shell vulnerabilities.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

SAP partner Onapsis, with cooperation from SAP, has released a threat report about critical vulnerabilities in ICM.  The regularly scheduled security updates for multiple SAP products also include updates for products affected by Log4Shell vulnerabilities.


Affected platforms

The following platforms are known to be affected:

The following platforms are also known to be affected:

These SAP products:

  • Internet of Things Edge Platform
  • SAP 3D Visual Enterprise Viewer
  • SAP Adaptive Server Enterprise
  • SAP Business Client
  • SAP Business Objects Web Intelligence (BI Launchpad)
  • SAP Commerce
  • SAP Content Server
  • SAP Customer Checkout
  • SAP Data Intelligence
  • SAP Dynamic Authorization Management
  • SAP ERP HCM (Portugal)
  • SAP NetWeaver (ABAP and Java application Servers)
  • SAP NetWeaver and ABAP Platform
  • SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel)
  • SAP NetWeaver Application Server Java
  • SAP NetWeaver AS ABAP (Workplace Server)
  • SAP S/4HANA
  • SAP S/4HANA (Supplier Factsheet and Enterprise Search for Business Partner, Supplier and Customer)
  • SAP Solution Manager (Diagnostics Root Cause Analysis Tools)
  • SAP Web Dispatcher

Threat details

SAP partner Onapsis releases Threat Report for ICM

In cooperation with SAP, Onapsis has released a Threat Report about SAP Internet Communication Manager (ICM), which is a core component of SAP business applications such as NetWeaver application server. One of the three vulnerabilities affecting ICM is known as CVE-2022-22536, and it has a CVSSv3 score of 10 as the exploit is simple, requires no previous authentication, and the payload can be sent through HTTP(S).

CISA have released an alert, which cautions that affected organisations may experience theft of sensitive data, financial fraud, disruption of mission-critical business processes, ransomware, and halt of all operations.


Introduction

SAP has released security updates to address vulnerabilities affecting multiple SAP products, including products impacted by Log4Shell vulnerabilities. Apart from aforementioned Log4Shell vulnerabilities, fifteen other vulnerabilities address code injection, information disclosure, cross site scripting, improper input validation, missing authorisation check, and others. An attacker could exploit these vulnerabilities to take control of an affected system.

NHS Digital response to Log4Shell

This alert is part of NHS Digital's wider response to the Log4Shell remote code execution vulnerability. For more information on Log4Shell itself, please visit our cyber alerts article Log4Shell RCE Vulnerability CC-3989.
 

Additional SAP systems may be vulnerable and affected organisations should regularly review SAP's Central Security Note for Remote Code Execution vulnerability associated with Apache Log4j 2 component. Note: SAP credentials are required to view the Security Note.

NHS and social care organisations are invited to use the Cyber Associates Network to find out additional information and participate in discussion about the Log4Shell remote code execution vulnerability and affected SAP products.


Remediation advice

Affected organisations are encouraged to review the SAP Security Notes for February 2022 and the Onapsis Threat Report on critical ICM vulnerabilities and apply the necessary updates.



CVE Vulnerabilities

Last edited: 10 February 2022 12:27 pm