Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SAP Critical Vulnerability - 20241009003 #1026

Merged
merged 121 commits into from
Oct 9, 2024
Merged
Changes from all commits
Commits
Show all changes
121 commits
Select commit Hold shift + click to select a range
278edae
SolarWinds Releases Patches for Access Rights Manager vulnerabilities…
LSerki Feb 19, 2024
c3843ff
Format markdown files
actions-user Feb 19, 2024
19a0bea
Merge branch 'main' into main
DGovEnterprise Feb 19, 2024
8f618ef
Format markdown files
actions-user Feb 19, 2024
f609904
Merge branch 'main' into main
DGovEnterprise Feb 19, 2024
7ce4db9
Merge branch 'wagov:main' into main
LSerki Feb 26, 2024
1085825
Junos OS RCE Vulnerability - 20240226002
LSerki Feb 26, 2024
3a8ebc5
Format markdown files
actions-user Feb 26, 2024
32a6776
Merge branch 'wagov:main' into main
LSerki Mar 8, 2024
d4b486a
Windows Themes Spoofing Vulnerability - 20240308003
LSerki Mar 8, 2024
6b07edd
Format markdown files
actions-user Mar 8, 2024
a69b437
Windows Themes Spoofing Vulnerability - 20240308003 - edited
LSerki Mar 8, 2024
f8e4c95
Merge branch 'wagov:main' into main
LSerki Mar 18, 2024
ad72a95
Akamai Kubernetes Vulnerability - 20240318002
LSerki Mar 18, 2024
60190b7
Format markdown files
actions-user Mar 18, 2024
9faea7b
Merge branch 'wagov:main' into main
LSerki Mar 27, 2024
0fa90ae
CISA Releases Multiple Critical Infrastructure Related Advisories - 2…
LSerki Mar 27, 2024
0b47143
Format markdown files
actions-user Mar 27, 2024
6f8fded
Merge branch 'wagov:main' into main
LSerki Apr 8, 2024
e61faa2
PGAdmin Remote Code Execution Vulnerability - 20240408001
LSerki Apr 8, 2024
b26ffaa
Format markdown files
actions-user Apr 8, 2024
47c8377
Merge branch 'main' into main
DGovEnterprise Apr 8, 2024
d01dc78
Update 20240408001-PGAdmin-Remote-Code-Execution-Vulnerability.md
DGovEnterprise Apr 8, 2024
d4849d9
Format markdown files
actions-user Apr 8, 2024
603cee1
Merge branch 'wagov:main' into main
LSerki Apr 15, 2024
1d093d3
Palo Alto Networks PAN-OS Command Injection Vulnerability added to CI…
LSerki Apr 15, 2024
fe1b80e
Format markdown files
actions-user Apr 15, 2024
a306442
Merge branch 'wagov:main' into main
LSerki Apr 15, 2024
7baaae6
Palo Alto Networks PAN-OS Command Injection Vulnerability added to CI…
LSerki Apr 15, 2024
c00daef
Format markdown files
actions-user Apr 15, 2024
5a1258f
Update 20240415001-PaloAlto-Networks-PAN-OS-Command-Injection-Vulnera…
DGovEnterprise Apr 15, 2024
5f3fe63
Format markdown files
actions-user Apr 15, 2024
03077aa
Merge branch 'main' into main
DGovEnterprise Apr 15, 2024
5f584d2
Merge branch 'wagov:main' into main
LSerki Apr 18, 2024
80309c7
Google Chrome Multiple RCE Vulnerabilities - 20240418002
LSerki Apr 18, 2024
a3ee4fe
Format markdown docs
LSerki Apr 18, 2024
ee2dff0
Remove duplicate 20240415001-PaloAlto
LSerki Apr 18, 2024
1b02629
Update 20240418002-Google-Chrome-Multiple-RCE-Vulnerabilities.md
DGovEnterprise Apr 18, 2024
dc6cd3d
Format markdown docs
DGovEnterprise Apr 18, 2024
ce33eaa
Merge branch 'wagov:main' into main
LSerki Apr 19, 2024
c4c283c
Libreswan Popular VPN Software Vulnerability - 20240419004
LSerki Apr 19, 2024
06cb004
Format markdown docs
LSerki Apr 19, 2024
b74d3dc
Update 20240419004-Libreswan-Popular-VPN-Software-Vulnerability.md
DGovEnterprise Apr 19, 2024
ebe4ab0
Merge branch 'main' into main
DGovEnterprise Apr 19, 2024
90f2f1d
Merge branch 'main' into main
DGovEnterprise Apr 19, 2024
23f9188
Merge branch 'main' into main
DGovEnterprise Apr 19, 2024
bab24bb
Merge branch 'wagov:main' into main
LSerki Apr 22, 2024
91507bb
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability…
LSerki Apr 22, 2024
05d1d36
Format markdown docs
LSerki Apr 22, 2024
ebcb503
Merge branch 'main' into main
DGovEnterprise Apr 22, 2024
2422301
Update 20240422002-Microsoft-Edge-Chromium-based-Security-Feature-Byp…
DGovEnterprise Apr 22, 2024
ecc5c85
Merge branch 'wagov:main' into main
LSerki Apr 29, 2024
b9c34fd
Windows Kernel Elevation of Privilege Vulnerability - 20240429001
LSerki Apr 29, 2024
ba4f508
Format markdown docs
LSerki Apr 29, 2024
f431daf
Merge branch 'main' into main
DGovEnterprise Apr 29, 2024
1a57d23
Update 20240429001-Windows-Kernel-Elevation-of-Privilege-Vulnerabilit…
DGovEnterprise Apr 29, 2024
da09a7d
Merge branch 'wagov:main' into main
LSerki May 3, 2024
5249611
Acrobat Reader Vulnerability - 20240503003
LSerki May 3, 2024
786af2a
Format markdown docs
LSerki May 3, 2024
bf0756f
Merge branch 'wagov:main' into main
LSerki May 9, 2024
8459952
Google Chrome Arbitrary Code Execution Multiple Vulnerabilities - 202…
LSerki May 9, 2024
81958ce
Format markdown docs
LSerki May 9, 2024
4d6816b
Update 20240509001-Google-Chrome-Arbitrary-Code-Execution-Multiple-Vu…
DGovEnterprise May 10, 2024
e8a9443
Merge branch 'wagov:main' into main
LSerki May 13, 2024
e049466
Microsoft Edge (Chromium-based) Spoofing Vulnerability - 20240513003
LSerki May 13, 2024
38241bb
Format markdown docs
LSerki May 13, 2024
925488d
Merge branch 'main' into main
DGovEnterprise May 13, 2024
4c9da38
Update 20240513003-Microsoft-Edge-Chromium-based-Spoofing-Vulnerabili…
DGovEnterprise May 13, 2024
0831358
Merge branch 'wagov:main' into main
LSerki May 16, 2024
632727d
Cacti Command Injection and XSS Vulnerabilities - 20240516004
LSerki May 16, 2024
60042ed
Format markdown docs
LSerki May 16, 2024
25fa892
Ivanti EPMM Vulnerability - 20240523002
LSerki May 23, 2024
4af6c3e
Format markdown docs
LSerki May 23, 2024
f64eac7
Ivanti EPMM Vulnerability - 20240523002
LSerki May 23, 2024
4e97572
Ivanti EPMM Vulnerability - 20240523002
LSerki May 23, 2024
8f90a97
Merge branch 'wagov:main' into main
LSerki May 27, 2024
d1cccd7
Ivanti Endpoint Manager GetRulesetsSQL SQL Injection RCE Vulnerabilit…
LSerki May 27, 2024
5c2db64
Format markdown docs
LSerki May 27, 2024
1569b9f
Update 20240527003-Ivanti-Endpoint-Manager-GetRulesetsSQL-SQL-Injecti…
DGovEnterprise May 27, 2024
55a1844
Merge branch 'main' into main
DGovEnterprise May 27, 2024
881b4bf
Merge branch 'wagov:main' into main
LSerki Jun 26, 2024
0ee9136
WordPress Plugin Vulnerabilities - 20240626003
LSerki Jun 26, 2024
1348d13
Format markdown docs
LSerki Jun 26, 2024
5913319
Merge branch 'main' into main
DGovEnterprise Jun 26, 2024
2136702
GeoServer Urgent Advisory - 20240704002
LSerki Jul 4, 2024
02e2ee9
Format markdown docs
LSerki Jul 4, 2024
8c81113
Merge branch 'main' into main
DGovEnterprise Jul 4, 2024
1a85a9f
Merge branch 'wagov:main' into main
LSerki Jul 18, 2024
7740c9d
Ivanti Releases New Security Advisories - 20240718004
LSerki Jul 18, 2024
dfaf553
Format markdown docs
LSerki Jul 18, 2024
267b211
Merge branch 'wagov:main' into main
LSerki Jul 24, 2024
367f30e
Merge branch 'wagov:main' into main
LSerki Jul 31, 2024
391a852
Merge branch 'wagov:main' into main
LSerki Jul 31, 2024
5837f7c
Apple Releases Multiple Product Updates - 20240731004
LSerki Jul 31, 2024
b267951
Format markdown docs
LSerki Jul 31, 2024
1d81bb8
Update 20240731004
JadonWill Jul 31, 2024
f543f34
Format markdown docs
JadonWill Jul 31, 2024
2a52534
Merge branch 'wagov:main' into main
LSerki Aug 22, 2024
ed6d716
Azure Managed Instance for Apache Cassandra Elevation of Privilege Vu…
LSerki Aug 22, 2024
d7511a3
Format markdown docs
LSerki Aug 22, 2024
871ac3e
Update 20240822002
JadonWill Aug 22, 2024
b17f05a
Merge branch 'wagov:main' into main
LSerki Sep 6, 2024
10375ef
Cisco Publishes Critical Update - 20240906003
LSerki Sep 6, 2024
9dfdf10
Format markdown docs
LSerki Sep 6, 2024
ccd0fe4
Cisco Publishes Critical Update - 20240906003
LSerki Sep 6, 2024
21a2f89
Format markdown docs
LSerki Sep 6, 2024
0001152
Update 20240906003
JadonWill Sep 6, 2024
b37ba42
Format markdown docs
JadonWill Sep 6, 2024
aec8722
Merge branch 'wagov:main' into main
LSerki Sep 13, 2024
503aca1
SolarWinds Critical Update - 20240913001
LSerki Sep 13, 2024
dfcdf4c
Format markdown docs
LSerki Sep 13, 2024
facbbf9
SolarWinds Critical Update - 20240913001
LSerki Sep 13, 2024
83dce58
Merge branch 'wagov:main' into main
LSerki Sep 26, 2024
85d4b0a
CISA Releases OT and ICS Advisory - 20240926002
LSerki Sep 26, 2024
ec85a29
Format markdown docs
LSerki Sep 26, 2024
d507c82
Update 20240926002
JadonWill Sep 26, 2024
50e2494
Merge branch 'wagov:main' into main
LSerki Oct 9, 2024
3ed9daf
SAP Critical Vulnerability - 20241009003
LSerki Oct 9, 2024
d7b8a37
Format markdown docs
LSerki Oct 9, 2024
2626ec8
Update 20241009003
JadonWill Oct 9, 2024
b634afc
Format markdown docs
JadonWill Oct 9, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 21 additions & 0 deletions docs/advisories/20241009003-SAP-Critical-Vulnerability.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# SAP Critical Vulnerability - 20241009003

## Overview

In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.

## What is vulnerable?

| Product(s) Affected | Version(s) | CVE | CVSS | Severity |
| -------------------------------------------------- | ---------------------------------- | ------------------------------------------------------------------ | ---- | ------------ |
| SAP BusinessObjects Business Intelligence Platform | ENTERPRISE 430 <br> ENTERPRISE 440 | [CVE-2024-41730 ](https://nvd.nist.gov/vuln/detail/CVE-2024-41730) | 9.8 | **Critical** |

## What has been observed?

There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.

## Recommendation

The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of *48 hours...* (refer [Patch Management](../guidelines/patch-management.md)):

- SAP advisory: <https://support.sap.com/en/my-support/knowledge-base/security-notes-news/october-2024.html>