Advisory
On 09.05.2023 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within Reprise License Manager.
SAP Note 3328495 addresses "Multiple vulnerabilities associated with Reprise License Manager 14.2 component used with SAP 3D Visual Enterprise License Manager" to prevent denial of service (dos) with a hot news risk for exploitation.
A workaround does exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Denial of Service (DoS) attacks that take a system offline may lead to significant cost for the company, studies quantify the costs in average between 4 and 5 millions dollars. Business continuity requires SAP systems staying online. The CVSS scores or vulnerability descriptions are not enough to represent how a simple bug can lead to a significant loss for companies.
Risk specification
This SAP security note addresses several vulnerabilities identified in Reprise License Manager version 14.2 is used by SAP 3D Visual Enterprise License Manager and is prone to web-interface related vulnerabilities.Solution
Upgrade SAP 3D Visual Enterprise License Manager to version 15.0.1-sap2 or higher. Circumstances exist that prevent the timely installation of a patch provided by the manufacturer. In such cases, you may consider applying the suggested workaround as a temporary or compensating mitigation: "The vulnerable Reprise License Manager's (RLM) web interface is not required for operations. The workaround in the security note describes how to deactivate this web interface manually.Please follow below steps to disable the web interface (which already had been described in note 2088020):1. Stop the service by running unservice.cmd with administrator privileges2. Edit service.cmd file and add -nows at the line which starts RLM3. Start the service using service.cmd with administrator privileges".
- 7.8 [CVE-2023-33990] Denial of service (DOS) vulnerability in SAP SQL Anywhere
- 7.7 [CVE-2023-35871] Memory Corruption vulnerability in SAP Web Dispatcher
- 7.5 Denial of service (DOS) in SAP Commerce
- 7.5 [CVE-2020-6186] Denial of Service (DOS) Vulnerability in SAP Host Agent
- 7.5 [CVE-2022-28772]Denial of service (DOS) in SAP Web Dispatcher and SAP Netweaver (Internet Communication Manager)