Advisory
A note with CVSS 7.8 for component CA-ATP-SUP-2CL was released by SAP on 23.07.2024. The correction/advisory 3423268 was described with "[CVE-2023-30533] Prototype Pollution in SAP S/4 HANA (Manage Supply Protection)" and affects the system type SAP Fiori.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is weak security function within SAP Fiori.
Risk specification
The Manage Supply Protection App of SAP S/4HANA allows an authenticated attacker to manipulate JavaScript objects (prototype tainting) due to a vulnerability in the open source library SheetJS, which can lead to cross-site scripting or remote code execution.Solution
The vulnerable library SheetJS has been updated.
- 6.2 [CVE-2023-40623] Arbitrary File Delete via Directory Junction in SAP BusinessObjects Suite(installer)
- 5.0 [CVE-2023-29108] IP filter vulnerability in ABAP Platform and SAP Web Dispatcher
- 4.7 [CVE-2024-41732] Improper Access Control in SAP Netweaver Application Server ABAP
- 4.3 [CVE-2024-45277] Prototype Pollution vulnerability in SAP HANA Client
- 4.3 [CVE-2024-45282] HTTP Verb Tampering in SAP S/4 HANA(Manage Bank Statements)