Advisory
On 12.12.2023 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within BTP.
SAP Note 3411067 addresses "[Multiple CVEs] Escalation of Privileges in SAP Business Technology Platform (BTP) Security Services Integration Libraries" to prevent escalation of privileges with a hot news risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as project, the team suggests.
Risk specification
Update: This note has been re-released with enhancements in the 'Symptom', 'Reason and Prerequisites' and 'Solution' sections. SAP BTP Security Services Integration Libraries and Programming Infrastructures allow an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.Solution
The libraries @sap/xssec (for Node.js), com.sap.cloud.security (for Java), sap-xssec (for Python) and cloud-security-client-go (for Golang) have been updated.
- 9.1 [Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell
- 9.1 [CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA
- 7.3 [CVE-2024-21735] Improper Authorization check in SAP LT Replication Server