Advisory
On 10.12.2024 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within Java.
SAP Note 3542543 addresses "[CVE-2024-54197] Server-Side Request Forgery in SAP NetWeaver Administrator (System Overview)" to prevent server-side request forgery (ssrf) with a high risk for exploitation.
A workaround does exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Risk specification
A vulnerability in the SAP NetWeaver Administrator (System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints within the internal network by crafted HTTP requests due to missing authorization checks, resulting in Server Side Request Forgery (SSRF).Solution
The vulnerable servlet was removed. Circumstances exist that prevent the timely installation of a patch provided by the manufacturer. In such cases, you may consider applying the suggested workaround as a temporary or compensating mitigation: "Disable the System Overview application with the following steps:1. Open the Java System Properties in the NetWeaver Administrator (NWA). Click on "Show advanced properties" button and go to the "Filters" tab.2. Add a new filter with these settings: Action: "disable", Vendor: "sap.com", Component: "all components", Name mask: "tc~monitoring~webservice~app" 3. Save the changes and restart the cluster in order to apply the changes.".
Affected System
SAP Netweaver Application Server Java is part of the SAP NetWeaver Application Platform. It provides the complete infrastructure for deploying and running Java applications.
- The AS Java Home: SAP Netweaver Application Server Java wiki
- A dedicated SAP NetWeaver 7.40 Application Server for Java Security Guide exists.
The advisory is valid for
- 9.1 [CVE-2024-29415] Server-Side Request Forgery vulnerability in applications built with SAP Build Apps
- 8.1 [CVE-2021-33705] Server-Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Enterprise Portal
- 5.8 [CVE-2020-6282] Server-Side Request Forgery in SAP NetWeaver AS JAVA (IIOP service)
- 5.0 [CVE-2024-37171] Server-Side Request Forgery (SSRF) in SAP Transportation Management (Collaboration Portal)
- 5.0 [CVE-2024-41737] Server-Side Request Forgery (SSRF) in SAP CRM ABAP (Insights Management)