On February 8, 2022, SAP released security updates to address vulnerabilities affecting multiple products, including critical vulnerabilities affecting SAP applications using SAP Internet Communication Manager (ICM). SAP applications help organizations manage critical business processesโsuch as enterprise resource planning, product lifecycle management, customer relationship management, and supply chain management. Impacted organizations could experience:
Additionally, security researchers from Onapsis, in coordination with SAP, released a Threat Report describing SAP ICM critical vulnerabilities, CVE-2022-22536, CVE-2022-22532 and CVE-2022-22533. Onapsis also provides an open source tool to identify if a system is vulnerable and needs to be patched.
CISA recommends operators of SAP systems review SAPโs February 2022 Security Updates page, the Onapsis Research Labs Threat Report: SAP ICMAD Vulnerabilities, and the Onapsis GitHub page for more information and apply necessary updates and mitigations.
This product is provided subject to this Notification and this Privacy & Use policy.
Please share your thoughts.
We recently updated our anonymous product survey; weโd welcome your feedback.
github.com/Onapsis/onapsis_icmad_scanner
github.com/Onapsis/onapsis_icmad_scanner
onapsis.com/icmad-sap-cybersecurity-vulnerabilities?utm_campaign=2022-Q1-global-ICM-campaign-page&utm_medium=website&utm_source=third-party&utm_content=CISA-alert
onapsis.com/icmad-sap-cybersecurity-vulnerabilities?utm_campaign=2022-Q1-global-ICM-campaign-page&utm_medium=website&utm_source=third-party&utm_content=CISA-alert
wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+February+2022
wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+February+2022