UPDATE (January 19, 2015): Note 1951171 has been rereleased translated into English, since it was originally published in German.
NEW NOTE (January 14, 2015): Note 1964201 has been released after the official SAP post of January 12nd. The note fixes a directory traversal in INTRASTAT module.
SAP is a complex and ever changing system, whether because of changes introduced to SAP implementation to better suit the business, or through the application of Security Notes (Patches) to ensure that newly disclosed vulnerabilities are mitigated.
In order to provide a predictable and scheduled flow of vulnerability mitigation information and security patches, SAP releases the major part of their latest Security Notes information on the second Tuesday of every month. Due to this regular disclosure of new security issues that could potentially weaken the security of SAP systems within an organization, it’s highly recommended to carry out periodic assessments on a monthly basis at the very least.
At Onapsis we are very concerned about our client’s SAP system security and the state of SAP security in general. To assist our customers, we perform a detailed analysis of the monthly SAP Security Notes as soon as they are published. The goal of this is to provide SAP clients with detailed information about the newly released notes and vulnerabilities affecting their SAP systems, and to help guide their testing of these systems within their organization.
Between the last SAP Security Tuesday and the notes published in January, there were 19 SAP Security notes (taking into account 7 Support Packages and 12 Patch Day Notes). There were notes published by external security researchers from which, Onapsis Research Labs reported SAP Security Note 2109565 by researchers Sergio Abraham, Nahuel D. Sánchez and Fernando Russ.
The plot graph illustrates the distribution of CVSS scores across the Security Notes released. The only notes taken into account were the ones for which SAP set a CVSS (6 out of the 19 SAP Security Notes). As it’s represented in the graph, the SAP Security Notes range values go from 4.9 to 8.5 with a median of 6.0.