Advisory
A note with CVSS 8.2 for component SCM-IBP-XLS was released by SAP on 09.05.2023. The correction/advisory 3323415 was described with "[CVE-2023-29080] Privilege escalation vulnerability in SAP IBP, add-in for Microsoft Excel" and affects the system type SAP Integrated Business Planning.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is code injection within SAP Integrated Business Planning.
Risk specification
The installer of SAP IBP, add-in for Microsoft Excel (Excel Add-in) allows an authenticated attacker to add an InstallScript custom action during installation time resulting in an escalation of privileges.Solution
The application no longer allows this kind of attack
The advisory is valid for
- SOP_EXCEL_ADDON 224
- SOP_EXCEL_ADDON 231
- SOP_EXCEL_ADDON 232
- SOP_EXCEL_ADDON 233
- SOP_EXCEL_ADDON 234
- SOP_EXCEL_ADDON 3.0
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Customer Checkout
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Cloud Foundry
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP HANA XSA
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services On Premise Edition