SAP security note 3109577, "Code Execution Vulnerability in SAP Commerce for China". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Commerce, localization for China uses open source software components with multiple vulnerabilities, potentially allowing code execution attacks. The affected components include XStream versions with the following CVEs:
- CVE-2021-21341
- CVE-2021-21342
- CVE-2021-21349
- CVE-2021-21343
- CVE-2021-21344
- CVE-2021-21346
- CVE-2021-21347
- CVE-2021-21350
- CVE-2021-21351
- CVE-2021-21345
- CVE-2021-21348
This vulnerability allows attackers to execute arbitrary code, potentially compromising the confidentiality, integrity, and availability of the affected systems.
Solution
Update SAP Commerce: patch to version 1905.32 or above. If using SAP Commerce, localization for China package 2001, download SP00 patch level 01. Otherwise, first upgrade to 2001.
Download and install the patch: visit the SAP Software Download Center, navigate to Access downloads under Types of Software > Support Packages & Patches, select the Downloads category and search for "sap china commerce loc", then choose SAP CHINA COMMERCE LOC 2001 and Maintenance Product. Download the patch CN_COMMERCE_LOC_2001_1-80005735.ZIP and follow the installation guide to apply it.
Workaround: this is a temporary fix, SAP recommends applying the official patch. Download the latest xstream jar from the groupId com.thoughtworks.xstream, replace the existing xstream jar in {HYBRIS_HOME}/hybris/bin/custom/chinesewechatwebservices/lib/, update the classpath entry in {HYBRIS_HOME}/hybris/bin/custom/chinesewechatwebservices/.classpath to reference the new jar, then stop the server, run "ant clean all" in {HYBRIS_HOME}/hybris/bin/platform, and restart the server.
For FAQs, refer to SAP Note 3124663.
CVSS
Score 9.9 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References
Affected components
- Y_CN_COMMERCE_LOC: 2001
Full note on SAP: SAP Support Launchpad note 3109577
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
