Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3413475
was released on
09.01.2024 and deals with
"[Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell" within SAP Edge Integration.
We advice you to follow the instructions, to resolve
escalation of privileges
with a
hot news potential for exploitation
in component BC-CP-IS-EDG-DPL.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as monthly patch process.
Risk specification
SAP Edge Integration Cell does use SAP BTP Security Services Libraries that are vulnerable to an escalation of privileges, allowing an attacker to get obtain arbitral authorizationsSolution
Edge Integration Cell has been updated with the latest version of the SAP BTP Security Integration Libraries and Programming Infrastructure
- 9.1 [Multiple CVEs] Escalation of Privileges in SAP Business Technology Platform (BTP) Security Services Integration Libraries
- 9.1 [CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA
- 7.3 [CVE-2024-21735] Improper Authorization check in SAP LT Replication Server