SAP Security Notes Review: October 2023
10 October 2023

Overview
SAP’s security patch day for October 2023 has seen the release of seven OSS SAP security notes. In summary, onenote has been classified as critical and six as medium based on CVSS v3.0 Rating.

Two notes have been released for:
- SAP NetWeaver AS JAVA
In addition, single notes have been released for:
- SAP BusinessObjects
- SAP PowerDesigner
- SAP Business One
- SAP S/4HANA
- SAP Business Client

Vulnerabilities: October 2023 Highlights
[CVE-2023-42474] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Web Intelligence (SAP Note 3372991)
SAP BusinessObjects Web Intelligence does not sufficiently encode user-controlled inputs, thus allowing an attacker to send a malicious link to a user. Accordingly, this link could then be used to retrieve sensitive information.
[CVE-2023-40310] Missing XML Validation vulnerability in SAP PowerDesigner Client (BPMN2 import) (SAP Note 3357154)
Due to insufficiencies in the SAP PowerDesigner Client, BPMN2 XML documents imported from an untrusted source are not adequately validated. As a result, URLs of external entities in a BPMN2 file, although not used, would be accessed during an import. A successful attack could consequently impact the availability of the SAP PowerDesigner Client.
[CVE-2023-41365] Information Disclosure vulnerability in SAP Business One (B1i) (SAP Note 3338380)
SAP Business One (B1i) allows an unauthorised attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure.





