Advisory
A note with CVSS 10.0 for component BC-FES-BUS-DSK was released by SAP on 10.04.2018. The correction/advisory 2622660 was described with "Security updates for the browser control Google Chromium delivered with SAP Business Client" and affects the system type SAP GUI / Frontend.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is code injection within SAP GUI / Frontend.
Risk specification
Update: This note has been re-released with updated ‘Solution’ and ‘Support Packages & Patches’ information. - Various vulnerabilities on the client via Browser (IE, Chrome etc.) controls: DoS, information disclosure, code injection.Solution
Every new SAP Business Client patch contains the most current stable major release of the Chromium browser control. (In case of Internet Explorer, it's a standard .net patch).
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Customer Checkout
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Cloud Foundry
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP HANA XSA
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services On Premise Edition