Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 2494184
was released on
08.08.2017 and deals with
"Cross-Site Request Forgery (CSRF) vulnerability in multiple SAP Sybase products" within Sybase platform.
We advice you to follow the instructions, to resolve
cross-site request forgery (xsrf)
with a
medium potential for exploitation
in component BC-SYB-SQA.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as part of maintenance.
Risk specification
SAP Sybase Cockpit, SAP Control Center (SCC), SQL Anywhere Monitor, and SQL Anywhere On Demand Edition Cloud Console administration tools allow an unauthenticated attacker to trick an authenticated user to send unintended request to the Web server.Solution
The SWF files, which did not contain proper validation, are re-compiled with an up-to-date version of Adobe Flex SDK.
The advisory is valid for
- SYBASE REPLICATION SERVER 15.7.1 2
- SIQ 16.0 2
- SY_ESP_SERVER 5.1 2
- SYBASE_ESP_ADAPTER_FOR_F.I.X. 5.1 2
- SYBASE_ESP_ADAP_FOR_OPEN_ADAP 5.1 2
- SYBASE_SQL_ANYWHERE_SERVER SQL_16.0 2
- SYBASE_SQL_ANYWHERE_SERVER 17.0 6
- SYBASE_ESP_STUDIO 5.1 2
- SY_ESP_ADAPTER_NYSE_TECH_MAMA 5.1 2
- SY_ESP_ADAP_TIBCO_RENDEZVOUS 5.1 2
- SY_ESP_ADAPTER_ADOBE_FLEX 5.1 2
- SY_ESP_ADAP_HTTP_OUTBOUND 5.1 2
- SY_ESP_ADAP_LOG_FILE_INPUT 5.1 2
- SY_ESP_ADD_IN_MICROSOFT_EXCEL 5.1 2
- SY_ESP_ADAP_SL_RTVIEW 5.1 2
- SYBASE_ASE_SERVER 15.7 7
- SYBASE_ASE_SERVER 16.0 13
- SYBASE_ASE_CE_SERVER 15.7
- 9.9 [CVE-2021-33690] Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure (Component Build Service)
- 7.6 [CVE-2020-6275] Server Side Request Forgery vulnerability in SAP NetWeaver AS ABAP
- 5.5 Cross-Site Request Forgery (CSRF) vulnerability in Cash Management
- 5.4 Cross-Site Request Forgery (CSRF) vulnerability in S/4HANA Finance for advanced payment management
- 5.4 Cross-Site Request Forgery (CSRF) vulnerability in S/4HANA OP2020, OP1909 in Import Financial Plan Data