SAP behebt kritischen SSRF-Fehler in den Adobe Document Services von NetWeaver

Teilen:

SAP has issued patches for 16 vulnerabilities, including a critical SSRF flaw in NetWeaver’s Adobe Document Services.

SAP addressed 16 vulnerabilities as part of its December 2024 Security Patch Day. The company released nine new and four updated security notes.

The most severe of these vulnerabilities is a critical issue, tracked as CVE-2024-47578 (CVSS score of 9.1), in the Adobe Document Service component of NetWeaver. An attacker with administrative privileges can exploit the vulnerability to send a crafted request from a vulnerable web application. Successful exploitation can allow attackers to read or modify any file and/or make the entire system unavailable.

The vulnerability impacts versions ADSSSAP 7.50.

“Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability.” reads the advisory. “On successful exploitation, the attacker can read or modify any file and/or make the entire system unavailable.”

The company also addressed other two vulnerabilities, tracked as  CVE-2024-47579 and CVE-2024-47580, as part of the same security notes that was labeled as ‘hot news’.

Bot vulnerabilities are medium-severity issues that could be exploited by an attacker with administrative access to read files on the server.

“These vulnerabilities, tracked as CVE-2024-47578, CVE-2024-47579, and CVE-2024-47580, collectively expose organizations to potential server-side request forgery (SSRF), unauthorized file access, and information disclosure.” reads the analysis published by Onapsis.

SAP also addressed a Cross-Site Scripting (XSS) vulnerability (CVSS score of 8.8), tracked as CVE-2024-47590, in Web Dispatcher.

The company fixed an Information Disclosure vulnerability through Remote Function Call (RFC), tracked as CVE-2024-54198 (CVSS score of 8.5) in SAP NetWeaver Application Server ABAP

The company is not aware of attacks in the wild exploiting one of the issues addressed with the release of December 2024 Security Patch Day.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
5:11 am, März 17, 2025
Wetter-Symbol 5°C
L: 5° | H: 6°
overcast clouds
Luftfeuchtigkeit: 80 %
Druck: 1028 mb
Wind: 7 mph NNE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 6:09 am
Sonnenuntergang: 6:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
5° | 6°°C 0 mm 0% 10 mph 80 % 1028 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 12 mph 69 % 1027 mb 0 mm/h
Mi. März 19 9:00 pm
Wetter-Symbol
3° | 15°°C 0 mm 0% 6 mph 82 % 1022 mb 0 mm/h
Do. März 20 9:00 pm
Wetter-Symbol
8° | 16°°C 0 mm 0% 8 mph 74 % 1021 mb 0 mm/h
Fr. März 21 9:00 pm
Wetter-Symbol
9° | 13°°C 0.2 mm 20% 6 mph 93 % 1015 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
3° | 5°°C 0 mm 0% 7 mph 80 % 1028 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
5° | 6°°C 0 mm 0% 10 mph 74 % 1028 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
7° | 8°°C 0 mm 0% 10 mph 63 % 1028 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 10 mph 56 % 1027 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 10 mph 73 % 1028 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 9 mph 76 % 1028 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 9 mph 67 % 1027 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 7 mph 69 % 1026 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€76,701.74
-1.11%
Ethereum(ETH)
€1,748.23
-1.30%
Fesseln(USDT)
€0.92
-0.01%
XRP(XRP)
€2.16
-1.55%
Solana(SOL)
€118.26
-4.86%
USDC(USDC)
€0.92
-0.01%
Dogecoin(DOGE)
€0.158244
-1.75%
Shiba Inu(SHIB)
€0.000012
3.49%
Pepe(PEPE)
€0.000006
-4.59%
Peanut das Eichhörnchen(PNUT)
€0.189641
20.47%
Nach oben scrollen