Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3218159
was released on
08.11.2022 and deals with
"Insufficient Session Expiration in Central Fiori Launchpad" within SAP UI5 SAP Fiori.
We advice you to follow the instructions, to resolve
insufficient security function
with a
medium potential for exploitation
in component CA-FLP-FE-COR.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as part of maintenance.
Risk specification
When an application from a foreign system is opened in the central Fiori launchpad, a new session to this system is established. Due to an error in the software, logout from the system does not terminate the separate session. Which can be used by a hacker, if the system is compromised.Solution
The code has been updated to properly terminate the session when logout is performed.