cancel
Showing results for 
Search instead for 
Did you mean: 

SAP Business One 10 Vulnerabilities

kfumanal
Explorer
0 Kudos

Dear all,

One of our customers need to know if it is affected by some vulnerabilities detected during an audit process.

This are the main points:

  1. Apache Log4j SEoL (<=1.x) – The plug in provides this finding as proof of vulnerability:
    1. kfumanal_0-1713161615568.png

       

    2. Questions: Are the servers using SAP Business objects 4.0 and if so can it be upgraded to 4.2 or 4.3 as referenced here: Solved: How is BO impacted by Log4j vulnerability? - SAP Community

                                                               i.      If not using this library file, can it be deleted?

  1. ASP.NET Core SEoL – The plug in has found multiple EOL version of ASP.NET core including 2.0.13103.0, 2.2.8, 3.1.29
    1. Is SAP using these ASP.NET versions?  If so can ASP.NET be upgraded independently of any SAP software (BusinessOne or Business Objects Enterprise)?
  2. Microsoft.NET Core SEoL - The plug in has found multiple EOL version of .NET core including 10.16.5115, 1.1.13.1809, 2.0.9.26615, 2.2.8.28209, 3.1.29.31617
    1. Is SAP using these ASP.NET versions?  If so can .NET be upgraded independently of any SAP software (BusinessOne or Business Objects Enterprise)?
  3. Apache 2.4.x < 2.4.58 Multiple Vulnerabilities – The plug in provides this finding as proof of vulnerability:
    1. kfumanal_1-1713161615569.png
    2. Can Apache be upgraded independent of SAP Business One?

 

For the first point (Log4j), we have the 3 SAP notes that help us to know the affectation of the vulnerability detected in the following SAP Forum link:

https://community.sap.com/t5/technology-q-a/how-is-bo-impacted-by-log4j-vulnerability/qaq-p/12651273

I need to know if there are any specific information regarding points 2, 3 and 4.

Kind regards,

Accepted Solutions (0)

Answers (0)