Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

How to Find SAP Security Note from NCICC Vulnerability?

Former Member
0 Kudos


Hi Community, we receive list of SAP and other vulnerabilities from NCCIC. For example:

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-7355

"SQL injection vulnerability in SAP BI Universal Data Integration allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to the J2EE schema."

How can I find out if a SAP security note is out there for this particular vulnerability and/or if it is relevant for our release?

Thanks!

4 REPLIES 4

Former Member
0 Kudos

Start with Patch Day notes https://websmp205.sap-ag.de/securitynotes

and also run RSECNOTE

and to be really sure, open an OSS message and ask SAP.

Not sure if there is a cross-list of nist vulnerabilities to oss notes.  Will be interesting to see replies to this question.

Former Member
0 Kudos

Hi,

Click on the link provided by NIST and it takes you to the advisory on the Onapsis website.  Register and download the advisory and it includes the note + relevant info (1773651).  You won't get spammed.  They are a good bunch of guys (and girls).

0 Kudos

Just incase: you should only download code sources from SAP via Service Market Place, not via transports or external files.

It is also best to use the SOLMAN system recommendations for SAP related security notes. It includes all of them and not just those of specific researchers.

SAP also offers an optional evaluation service. See SAP Note 1839420. Some notes must just go in... others are better options for upgrades or support packs and have mitigation possibilities.

Cheers,

Julius

0 Kudos

Anyone d/l bug fix source code from anywhere other than SAP would deserve everything they got!