Advisory
A note with CVSS 9.8 for component BC-SYB-PD was released by SAP on 12.04.2022. The correction/advisory 3189429 was described with "[CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in PowerDesigner Web (up to including 16.7 SP05 PL01)" and affects the system type Java.
A workaround exists, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is remote code execution within Java.
Risk specification
PowerDesigner Web uses a version of Spring Framework which has Remote Code Execution vulnerability. The default installation which is based on JRE 1.8 is not vulnerable. In case you use another java runtime, or if you upgraded your Java to version 1.9 or higher, then your installation may be subject to Spring4Shell vulnerability.Solution
Upgrade the PowerDesigner to a version which is not vulnerable to the remote code execution vulnerability Although an alternative solution exists, it is advisable to apply the correction! This is the workaround, which was suggested by the SAP security experts: "Use Java runtime environment 1.8 as a workaround as this java version is not vulnerable.".
Affected System
SAP Netweaver Application Server Java is part of the SAP NetWeaver Application Platform. It provides the complete infrastructure for deploying and running Java applications.
- The AS Java Home: SAP Netweaver Application Server Java wiki
- A dedicated SAP NetWeaver 7.40 Application Server for Java Security Guide exists.
The advisory is valid for
- SYBASE_POWERDESIGNER_WEBPORTAL 16.7
- 10.0 [CVE-2023-27497] Multiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge and EventLogServiceCollector)
- 9.8 [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Profitability Analytics
- 9.8 [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Checkout
- 9.8 [CVE-2022-22965] Central Security Note for Remote Code Execution vulnerability associated with Spring Framework
- 9.8 [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in in SAP Business One Cloud