Below we have summarized the topics of the second quarter in 2022 for you.
SAP
Security updates for the browser control Google Chromium delivered with SAP Business Client
Implementation of the patch
SAP Note: 2622660
10
SAP
Information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)
Implementation of the patch
SAP Note: 3226411
8.3
SAP
Information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Open Document)
Implementation of the patch
SAP Note: 3210823
8.2
SAP
Privilege escalation vulnerability in SAP SuccessFactors attachment API for Mobile Application
Implementation of the patch and entitlement adjustment
SAP Note: 3226411
8.1
SAP
Windows Unquoted Service Path issue in SAP Business One
Updating the SAP Business One component
SAP Note: 3223392
7.8
SAP
Central Management Server Information Disclosure in Business Intelligence Update
Updating the SBOP BI Platform Versionn
SAP Note:2998510
7.8
SAP
Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (CMC)
Updating the SBOP BI Platform Version
SAP Note: 3217303
7.7
SAP
Code Injection vulnerability in SAP Business One
Implementation of the patch and manual adjustments
SAP Note: 3191012
Attention: The block list of files should be maintained in the Business One Manager under the general settings in order to upgrade to version 10.0.
7.4
SAP
Insufficient Firefighter Session Expiration in SAP GRC Access Control Emergency Access Management
Importing the correction instructions
SAP Note: 3237075
7.1
Category
Security gap
Solution/ Workaround
To be noted
CVSS
Python
15-year-old vulnerability allows attackers to overwrite important system files
Distributions have not been able to offer a fix accordingly so far. Future update could fix this bug
Heise: Security message
–
*Common Vulnerability Scoring System (CVSS)
0,0 – 10,0 (keine Bewertung – kritisch)
If you would like more detailed information on a specific topic, please feel free to contact our IT Security department at any time.
FIS-ASP Application Service Providing und IT-Outsourcing GmbH
Röthleiner Weg 4
D-97506 Grafenrheinfeld
Tel.: +49 97 23 / 91 88-500
Fax: +49 97 23 / 91 88-600
FIS-ASP Application Service Providing und IT-Outsourcing GmbH
Röthleiner Weg 4
D-97506 Grafenrheinfeld
Phone.: +49 97 23 / 91 88-500
Fax: +49 97 23 / 91 88-600
info@fis-asp.de
Also during the Christmas season, FIS-ASP GmbH continues its social commitment under the motto “Donations instead of gifts”.
In October, four ambitious talents began their journey towards a career in the SAP envi-ronment. The 6-month intensive program at FIS-ASP not only promises in-depth training, but also an exciting journey from theory to practice.
Last week we had a lot going on! 🏓
Our first in-house table soccer tournament took place and it was hot on the pitch.
The following link takes you to our download area. Here you can find information about the company, white papers and use cases.
We inform you about current changes in the area of IT security. Sign up and don’t miss any more information in the future.