Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SAP’s 13 December 2022 Security Patch Day issued 14 new security notes and updated five existing notes. The Canadian Centre for Cyber Security highlighted critical updates for SAP Business Client, SAP Commerce, SAP BusinessObjects Business Intelligence Platform, and SAP NetWeaver Process Integration. SAP’s detailed bulletin labels five individual entries “Hot News”; the other notes in the broader bulletin have different priorities. Whether a note applies depends on the SAP product and version you run.

What SAP published on 13 December 2022

SAP’s archived December 2022 Patch Day bulletin records 14 new Patch Day Security Notes and five updates to notes released earlier. That is 19 note actions, not 19 newly disclosed vulnerabilities: some entries revised older notes. SAP says Patch Day notes are generally released on the second Tuesday of each month, with notes published after that date counted with the following Patch Day.

The Canadian Centre for Cyber Security published advisory AV22-696 on the same date. Its summary identifies four product families with critical updates and recommends that users and administrators review the advisory and apply necessary updates. Its product-level framing is separate from SAP’s priority labels for individual notes.

Products and versions named in the critical-update advisory

The Canadian advisory lists these product/version groups. A listed version does not by itself prove that a particular installation is vulnerable; confirm applicability in the relevant SAP Security Note.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Product family Versions listed
SAP Business Client 6.5, 7.0, 7.70
SAP Commerce 1905, 2005, 2105, 2011, 2205
SAP BusinessObjects Business Intelligence Platform 420, 430
SAP NetWeaver Process Integration 7.5 in the Canadian advisory; SAP’s note table shows 7.50

These groups come from Canadian Centre for Cyber Security advisory AV22-696.

SAP’s five “Hot News” entries

SAP’s bulletin uses the exact priority label “Hot News” for the following entries. CVSS scores below are those SAP published in 2022; they are severity scores, not evidence by themselves that a vulnerability was exploited in the wild.

Rank #2
Dell Computers PowerEdge R740 Server 2X Gold 6154 3.00Ghz 36-Core 384GB RAM 16x Caddies (Renewed)
  • Renewed server with the highest quality standards
  • Ideal for a robust enterprise environment or data center
  • All servers include power cords, and other parts detailed in full product description below
  • Custom configurations available upon request
SAP Security Note / CVE Issue and affected versions shown SAP priority SAP-published CVSS
2622660 Google Chromium browser-control security updates delivered with SAP Business Client; 6.5, 7.0, 7.70. The bulletin describes this as an update to an April 2018 note. Hot News 10.0
3239475 / CVE-2022-41267 Server-side request forgery in SAP BusinessObjects Business Intelligence Platform; 420, 430. Hot News 9.9
3273480 / CVE-2022-41272 Improper access control in SAP NetWeaver Process Integration (User Defined Search); 7.50. Hot News 9.9
3271523 / CVE-2022-42889 Remote code execution associated with Apache Commons Text in SAP Commerce; 1905, 2005, 2105, 2011, 2205. Hot News 9.8
3267780 / CVE-2022-41271 Improper access control in SAP NetWeaver Process Integration (Messaging System); 7.50. Hot News 9.4

The note IDs, issue descriptions, versions, priorities, and scores are from SAP’s archived Patch Day bulletin. Check each linked note in SAP’s support environment for its detailed affected-component scope and applicable correction instructions.

The bulletin also includes High and Medium priority issues

The five Hot News entries are not the full December bulletin. SAP also listed High-priority issues including code injection in SAP BASIS (CVE-2022-41264, CVSS 8.8), privilege escalation in SAP Business Planning and Consolidation (CVE-2022-41268, CVSS 8.53), information disclosure in SAP BusinessObjects BI Platform Program Objects (CVSS 8.2), cross-site scripting in SAP Commerce Webservices 2.0 / Swagger UI (CVSS 8.0), and vulnerabilities in SQLite bundled with SAPUI5 (CVSS 7.5).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Medium-priority entries included missing authorization checks in SAP Disclosure Management, cross-site scripting in SAP NetWeaver AS for Java, an open redirect in SAP Solution Manager, and other access-control, authentication, or redirect issues. These examples show why the rollup should not be read as if every issue had the same priority or affected the same SAP products.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to determine whether your SAP system needs a fix

  1. Inventory installed products and releases. Record the SAP product or component and exact release level for each system in scope.
  2. Find the relevant Security Note. SAP says customers can search Security Notes in Launchpad Expert Search over a selected date range. Search by note number or CVE when available, then inspect the note’s affected-product and version details.
  3. Check the note’s current revision and instructions. Compare your system with the note’s scope, correction, prerequisites, and any revisions in SAP’s support environment; the 2022 bulletin is an archived rollup, not a current assessment of your patch state.
  4. Prioritize and deploy through your change process. SAP recommends consulting its Support Portal and applying patches by priority to protect the SAP landscape. Plan the applicable change using your organization’s testing, approval, and maintenance procedures.

The Canadian advisory likewise tells administrators to review its guidance and apply necessary updates. Neither the advisory nor a matching version number replaces checking the detailed vendor note for the specific installation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.