https://raw.githubusercontent.com/ajmaradiaga/feeds/main/scmt/topics/Security-qa.xml SAP Community - Security 2024-05-09T20:01:52.259218+00:00 python-feedgen Security Q&A in SAP Community https://community.sap.com/t5/technology-q-a/using-btp-ips-is-it-possible-to-read-data-from-tables-or-else-other/qaq-p/13590987 Using BTP IPS, is it possible to read data from tables or else other function modules for ABAP ? 2024-02-01T13:41:54.167000+01:00 devaprakash_b https://community.sap.com/t5/user/viewprofilepage/user-id/204226 <P>Hello All,<BR /><BR />I would like to understand&nbsp;Using IPS, is it possible to read data from standard tables or else other function modules? I remember using SAP IDM ABAP connector it is possible to read data from tables as well as execute function modules apart from the standard BAPI_USER_CHANGE or RFC_READ_TABLE etc.,<BR /><BR />My requirement is to execute RFC enabled BAPI calls like RFC_READ_TABLE/RSAU_READ_LOG and expose the data as the Proxy api. Currently i am able to connect SAP ABAP NW 7.5 system to IPS as a proxy and able to read the roles, users and perform provisioning activities related to user using the Proxy api's .<BR /><BR /></P> 2024-02-01T13:41:54.167000+01:00 https://community.sap.com/t5/technology-q-a/su01-shows-role-assigned-via-position-but-the-role-does-not-appear-in-po13/qaq-p/13598269 SU01 shows role assigned via position but the role does not appear in PO13 2024-02-07T17:01:21.183000+01:00 dlouis https://community.sap.com/t5/user/viewprofilepage/user-id/199099 <P>In SU01, the user appears to have certain roles assigned at the position level.&nbsp; However, in PO13 the position does not contain a relationship for this role.&nbsp;&nbsp;</P> 2024-02-07T17:01:21.183000+01:00 https://community.sap.com/t5/technology-q-a/appgyver-platform/qaq-p/13610266 Appgyver Platform 2024-02-19T16:27:35.208000+01:00 fernandohs https://community.sap.com/t5/user/viewprofilepage/user-id/1400597 <P>I have a problem to access the platform appgyver, since a week the site is showing a message about a security certificate expired, anyone can help me ?</P> 2024-02-19T16:27:35.208000+01:00 https://community.sap.com/t5/technology-q-a/sap-gsoap-version-disclosure-vulnerability/qaq-p/13611195 SAP GSOAP VERSION DISCLOSURE VULNERABILITY 2024-02-20T10:38:32.337000+01:00 GanIYY https://community.sap.com/t5/user/viewprofilepage/user-id/1401250 <P>Hello,</P><P>We are facing security issue, SAP gsoap exposes its version information during network scanning,</P><P>Any ways to hide the version related information from SAP application ?</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="temp.PNG" style="width: 357px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/68070iF62A481AAE940651/image-size/large?v=v2&amp;px=999" role="button" title="temp.PNG" alt="temp.PNG" /></span></P> 2024-02-20T10:38:32.337000+01:00 https://community.sap.com/t5/technology-q-a/auth-object-to-restrict-access-to-global-data-client-level/qaq-p/13614222 auth. object to restrict access to global data/ client level 2024-02-21T11:20:11.441000+01:00 SAPSupport https://community.sap.com/t5/user/viewprofilepage/user-id/121003 <P>An authorization object needs to be applied to several roles.</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B> 2024-02-21T11:20:11.441000+01:00 https://community.sap.com/t5/technology-q-a/bapi-user-change-under-cua-environment/qaq-p/13624991 BAPI_USER_CHANGE under CUA environment 2024-03-01T10:33:58.265000+01:00 SAPSupport https://community.sap.com/t5/user/viewprofilepage/user-id/121003 <P>Hello SAP</P><P>We are trying to change user password by FM( BAPI_USER_CHANGE ).&nbsp; Our SAP system is running on CUA environment. We have checked restrictions of this FM under CUA.&nbsp; No special restriction were found.&nbsp;</P><P>I thought changing initial password will lead changing password of users on child system. Changing anohter item like first name &amp; last name will lead to changing those of user on child system. However nothing happened as we expected. So we didn't specified target child system.</P><P>Why anything happen ? Is ther any restriction for Functional Module under CUA environment ?</P><P>&nbsp;</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B> 2024-03-01T10:33:58.265000+01:00 https://community.sap.com/t5/technology-q-a/how-to-change-log-retention-period-about-user-change-documents-in-sap-hana/qaq-p/13625079 How to change log retention period about User Change Documents in sap hana 2024-03-01T11:36:09.912000+01:00 SAPSupport https://community.sap.com/t5/user/viewprofilepage/user-id/121003 <P>Dear SAP,</P><P>I wonder if there is a way to change the log retention period for permissions and profile items that are output when inquiring user change documents through transaction SUIM.</P><P>Whether it can be easily changed through setting,<BR />Please check if we need to develop a program that deletes data from a specific table and if there is any other way, please let us know.</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B> 2024-03-01T11:36:09.912000+01:00 https://community.sap.com/t5/technology-q-a/the-provided-authorization-grant-is-invalid/qaq-p/13627758 The provided authorization grant is invalid 2024-03-05T08:27:15.492000+01:00 Jwan_ https://community.sap.com/t5/user/viewprofilepage/user-id/175626 <P>Hello everyone,</P><P>I am getting the error: The provided authorization grant is invalid. Exception was: There is no trust between entities and <A href="https://eu2.hana.ondemand.com/services" target="_blank" rel="nofollow noopener noreferrer">https://eu2.hana.ondemand.com/services</A> in client 027</P><P>when entering the following parameters in BTP destination:</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jwan__0-1709622644105.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/75345iA49EF172FA91C267/image-size/medium?v=v2&amp;px=400" role="button" title="Jwan__0-1709622644105.png" alt="Jwan__0-1709622644105.png" /></span></P><P>&nbsp;</P><P>followed this tutorial blog:&nbsp;<BR /><A href="https://community.sap.com/t5/customer-relationship-management-blogs-by-sap/configuring-oauth-2-0-between-sap-hybris-cloud-for-customer-and-sap-cloud/ba-p/13323502" target="_blank">https://community.sap.com/t5/customer-relationship-management-blogs-by-sap/configuring-oauth-2-0-between-sap-hybris-cloud-for-customer-and-sap-cloud/ba-p/13323502</A></P><P>&nbsp;</P> 2024-03-05T08:27:15.492000+01:00 https://community.sap.com/t5/technology-q-a/how-to-request-an-enhancement-for-sap-security/qaq-p/13634550 How to request an Enhancement for SAP Security? 2024-03-11T18:15:51.602000+01:00 carl_shepherd https://community.sap.com/t5/user/viewprofilepage/user-id/774442 <P>Hi I want to suggest an enhancement to SAP Standard security functionality (PFCG) I tried to use&nbsp;2967362&nbsp;-&nbsp;How to submit an enhancement request for On-Premise Products but you are foced to choose a product. There seems to be no way to submit an enhancement to basis technology functionality. How can I submit a request for enhancement?&nbsp;</P><P>I want to suggest to add functionality to allow security admins to lock a role so that it cannot be transported, and or lock a role for changes. This would help solve an old and pernicious problem for large teams / systems where roles are updated by multiple people more or less concurrently leading to lots of trouble.&nbsp;</P><P>Cheers,</P><P>Carl</P> 2024-03-11T18:15:51.602000+01:00 https://community.sap.com/t5/technology-q-a/su01-account-type/qaq-p/13636554 SU01 account type 2024-03-13T09:26:05.242000+01:00 SAPSupport https://community.sap.com/t5/user/viewprofilepage/user-id/121003 <P>Dear Expert:</P><P>About su01 field "User Type", I confuse how to use.</P><P>For my current issue , other SAP system use (ALE and RFC) to communication . If I set User Type:Communication&nbsp; , it will face "<U>Password logon not possible (Initial password expired)</U> ".</P><P>I can set User Type: System , it work. For my current system use, just ALE &amp; RFC. We wish No need change password , password nerver expired. Which User Type useful for my need ?</P><P>~~<BR />Jeff</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B> 2024-03-13T09:26:05.242000+01:00 https://community.sap.com/t5/technology-q-a/restriction-of-transaction-code/qaq-p/13645508 Restriction of transaction code 2024-03-21T12:07:52.029000+01:00 SAPSupport https://community.sap.com/t5/user/viewprofilepage/user-id/121003 <P>We are localizing an authorization and role for support users when functional test the transaction codes there were data's that can view&nbsp; globally.</P><P>We understand that not all transaction code has the restriction for organization level.</P><P>Sample is for tcode OBY6 functional can see data from other countries and we have checked in Su24 there is no auth obj being pulled and one is for SE16 we understand that this can be limit only based on the table auth group.</P><P>Is there a possibility to restrict certain transaction codes on specific country only? These involved mostly with IT Support tcodes?</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B> 2024-03-21T12:07:52.029000+01:00 https://community.sap.com/t5/human-capital-management-q-a/using-iframe-in-learning-module/qaq-p/13645982 using iFrame in Learning Module 2024-03-21T17:32:46.506000+01:00 acarmanhani1 https://community.sap.com/t5/user/viewprofilepage/user-id/125013 <P><SPAN><SPAN class="">Hello community, </SPAN></SPAN></P><P><SPAN><SPAN class="">Considering the issue of third-party cookie deprecation&nbsp; (<A href="https://d.dam.sap.com/a/s3hKB1L/Third%20Party%20Cookies%20Frequently%20Asked%20Questions.pdf?rc=10" target="_blank" rel="noopener noreferrer">https://d.dam.sap.com/a/s3hKB1L/Third%20Party%20Cookies%20Frequently%20Asked%20Questions.pdf?rc=10</A>) and its impact on SAP SuccessFactors, I'm curious about the repercussions when using UI5 extensions (on BTP) embedded within <STRONG>iframes</STRONG> in the <STRONG>LMS</STRONG>. Would linking to open in a new tab address this problem? Are there any other impacts we should be aware of?</SPAN></SPAN></P><P><SPAN><SPAN class="">Thanks,</SPAN></SPAN></P><P><SPAN><SPAN class="">Anderson</SPAN></SPAN></P> 2024-03-21T17:32:46.506000+01:00 https://community.sap.com/t5/technology-q-a/no-saml2-sso-authentification-among-different-sap-system-with-nwbc/qaq-p/13652992 No SAML2 SSO authentification among different SAP system with NWBC 2024-03-28T23:02:45.405000+01:00 AnthoDKT https://community.sap.com/t5/user/viewprofilepage/user-id/865184 <P data-unlink="true"><SPAN>Hello,</SPAN></P><P data-unlink="true">Please find the description of the issue :<BR /><BR /><SPAN>When I first connect to SAP system SID1 with NWBC, I am going through the SAML2 workflow authentification, then when I am connecting to another system SID2, I am again asked to go through the SAML2 workflow authentification.</SPAN><BR /><BR /><SPAN>When I am reproducing the same in a web browser, connecting first to<EM> https://sapsid1.domain/sap/bc/ui2/nwbc/</EM>&nbsp; &nbsp;with SAML2 workflow authentification, and secondly&nbsp;connecting to&nbsp;</SPAN><EM>https://sapsid2.domain/sap/bc/ui2/nwbc/</EM>&nbsp;<SPAN>, I don't need to authenticate again for SID2 as the MYSAPSSO2 cookie is shared between both (If my understanding is right).</SPAN></P><P data-unlink="true"><BR /><SPAN>Could you please help us understand this difference of behavior between NWBC and a web browser ? How can I have this "unique" authentification in NWBC like the one in the browser ?</SPAN><BR /><BR /><SPAN>Thanks for your help,</SPAN></P><P data-unlink="true"><SPAN>Anthony</SPAN></P> 2024-03-28T23:02:45.405000+01:00 https://community.sap.com/t5/technology-q-a/to-find-out-and-analyze-what-tables-and-programs-user-accessed-past-6/qaq-p/13658637 To find out and analyze what tables and programs user accessed past 6 months using which roles. 2024-04-04T10:56:43.959000+02:00 SAPSupport https://community.sap.com/t5/user/viewprofilepage/user-id/121003 <P>we are trying to restrict S_PROGRAM with * value&nbsp;</P><P>To find out and analyze what tables and programs user accessed past 6 months.</P><P>1. we have checked the program/table usage via SM20 logs for users but is there any way to check in S/4&nbsp; system for program/table usage of user through which role it is being accessed through any other standard tcode /reports?</P><P><BR />2.If we have any other possible way to get the program/table usage of users and through which role it is being accessed through any GRC standard tcode/report?</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B> 2024-04-04T10:56:43.959000+02:00 https://community.sap.com/t5/technology-q-a/hey-team-can-i-know-how-to-see-the-security-events-logs-of-sap-hana/qaq-p/13662473 hey team, can i know how to see the security events logs of sap hana.. 2024-04-08T15:11:19.182000+02:00 ruzi https://community.sap.com/t5/user/viewprofilepage/user-id/1429600 <P>I have refered&nbsp;<A href="https://community.sap.com/t5/application-development-blog-posts/analysis-and-recommended-settings-of-the-security-audit-log-sm19-rsau/ba-p/13297094#jive_content_id_List_of_events" target="_self">https://community.sap.com/t5/application-development-blog-posts/analysis-and-recommended-settings-of-the-security-audit-log-sm19-rsau/ba-p/13297094#jive_content_id_List_of_events&nbsp;&nbsp;</A></P><P>but its about 2014, I m receiving different logs.. how can i get information from my new logs.. or is there any updation you have?</P> 2024-04-08T15:11:19.182000+02:00 https://community.sap.com/t5/technology-q-a/format-file-audit/qaq-p/13662707 Format file audit 2024-04-08T17:49:52.007000+02:00 basis_support_pl3_bis https://community.sap.com/t5/user/viewprofilepage/user-id/861815 2024-04-08T17:49:52.007000+02:00 https://community.sap.com/t5/technology-q-a/for-more-clarity/qaq-p/13663815 For more clarity 2024-04-09T12:21:58.206000+02:00 ruzi https://community.sap.com/t5/user/viewprofilepage/user-id/1429600 <P>Hi Sandra,</P><P>Thank u for this deep explanation, I need more clarity on some areas</P><UL><LI>5: Entry type<UL><LI>"q" = DDIC structure RSAUENTR2 version 1 without field SLGLTRM2</LI><LI>"2" = DDIC structure RSAUENTR2 version 2 including field SLGLTRM2</LI><LI>"5" = variable length record</LI></UL></LI><LI>you have mentioned 5 as a variable length.. which length does it holds?? bcoz i m clear with other things like length of user+username</LI></UL><P>what is 0000 - length of ?? + ?? . This u have mentioned.. what is the meaning of that?</P><P>And in this doc,&nbsp;<A href="https://community.sap.com/t5/application-development-blog-posts/analysis-and-recommended-settings-of-the-security-audit-log-sm19-rsau/bc-p/13663225" target="_self">https://community.sap.com/t5/application-development-blog-posts/analysis-and-recommended-settings-of...</A></P><P>every field has a defined length ,but u have here described with variable lengths, does this occurs in the latest version of sap?? Bcoz in this doc,its mentioned as</P><P>variable message has 64 bits,program has 40 like that.. and follows an order.. and here is there any order.. if possible can u provide a table like this.. so that i would be more helpful</P><P><STRONG>Field</STRONG><STRONG>Sub-field</STRONG><STRONG>Length</STRONG><STRONG>Description</STRONG></P><TABLE border="1" cellpadding="4"><TBODY><TR><TD>SLGTYPE</TD><TD>&nbsp;</TD><TD>&nbsp;</TD><TD>SysLog: LIKE structure RSLGETYP</TD></TR><TR><TD>&nbsp;</TD><TD>SLGFTYP</TD><TD>1</TD><TD>Entry type: "q" = version 1 without field<SPAN>&nbsp;</SPAN><SPAN>SLGLTRM2</SPAN>, "2" = version 2 including field<SPAN>&nbsp;</SPAN><SPAN>SLGLTRM2</SPAN></TD></TR><TR><TD>&nbsp;</TD><TD><SPAN>AREA</SPAN></TD><TD>2</TD><TD>Message area</TD></TR><TR><TD>&nbsp;</TD><TD><SPAN>SUBID</SPAN></TD><TD>1</TD><TD>Message name</TD></TR><TR><TD>SLGDATTIM</TD><TD>&nbsp;</TD><TD>&nbsp;</TD><TD>Time stamp (CHAR 16)</TD></TR><TR><TD>&nbsp;</TD><TD>DATE</TD><TD>8</TD><TD>Date in format YYYYMMDD</TD></TR><TR><TD>&nbsp;</TD><TD>TIME</TD><TD>6</TD><TD>Time in format hhmmss</TD></TR><TR><TD>&nbsp;</TD><TD>DUMMY</TD><TD>2</TD><TD>not used</TD></TR><TR><TD>SLGPROC</TD><TD>&nbsp;</TD><TD>&nbsp;</TD><TD>SysLog: LIKE RSLGPID structure</TD></TR><TR><TD>&nbsp;</TD><TD>UNIXPID</TD><TD>5</TD><TD>Process ID</TD></TR><TR><TD>&nbsp;</TD><TD>TASKTNO</TD><TD>5</TD><TD>Task</TD></TR><TR><TD>&nbsp;</TD><TD>SLGTTYP</TD><TD>2</TD><TD>Process type (short form)</TD></TR><TR><TD><SPAN>SLGLTRM</SPAN></TD><TD>&nbsp;</TD><TD>8</TD><TD>Terminal name (truncated)</TD></TR><TR><TD>SLGUSER</TD><TD>&nbsp;</TD><TD>12</TD><TD>User name</TD></TR><TR><TD>SLGTC</TD><TD>&nbsp;</TD><TD>20</TD><TD>Transaction</TD></TR><TR><TD>SLGREPNA</TD><TD>&nbsp;</TD><TD>40</TD><TD>Program</TD></TR><TR><TD>SLGMAND</TD><TD>&nbsp;</TD><TD>3</TD><TD>Client</TD></TR><TR><TD>SLGMODE</TD><TD>&nbsp;</TD><TD>1</TD><TD>External mode of an SAP dialog</TD></TR><TR><TD><SPAN>SLGDATA</SPAN></TD><TD>&nbsp;</TD><TD>64</TD><TD>Variable message data</TD></TR><TR><TD><SPAN>SLGLTRM2</SPAN></TD><TD>&nbsp;</TD><TD>20</TD><TD>Terminal name (continued), only available if SLGFTYP=2</TD></TR></TBODY></TABLE><P>&nbsp;</P> 2024-04-09T12:21:58.206000+02:00 https://community.sap.com/t5/technology-q-a/s-4hana-cloud-public-edition-security/qaq-p/13667172 S/4HANA Cloud Public Edition - Security 2024-04-11T17:00:34.342000+02:00 daan_fessl https://community.sap.com/t5/user/viewprofilepage/user-id/594230 <P>Hi Experts,<BR /><BR />S/4HANA Cloud Public Edition is offered as a SaaS application. This collects that access to S/4HANA Cloud Public Edition is possible from any location and from any device.</P><P>Apart from the discussion about this from a security perspective, I am curious about the technical possibilities to limit this to 'Our Customer' defined “trusted locations” based on conditional access rules such as countries, regions, external IP address of subnet, device, etc.?</P><P>What are the possibilities here?<BR /><BR />Thanks in advance!</P> 2024-04-11T17:00:34.342000+02:00 https://community.sap.com/t5/enterprise-resource-planning-q-a/sap-business-one-10-vulnerabilities/qaq-p/13670480 SAP Business One 10 Vulnerabilities 2024-04-15T08:18:48.701000+02:00 kfumanal https://community.sap.com/t5/user/viewprofilepage/user-id/433929 <P>Dear all,</P><P>One of our customers need to know if it is affected by some vulnerabilities detected during an audit process.</P><P>This are the main points:</P><OL><LI><STRONG>Apache Log4j SEoL (&lt;=1.x)</STRONG> – The plug in provides this finding as proof of vulnerability:<OL><LI><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kfumanal_0-1713161615568.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/96415iEE6A15D7F6D215BF/image-size/medium?v=v2&amp;px=400" role="button" title="kfumanal_0-1713161615568.png" alt="kfumanal_0-1713161615568.png" /></span><P>&nbsp;</P></LI><LI>Questions: Are the servers using SAP Business objects 4.0 and if so can it be upgraded to 4.2 or 4.3 as referenced here:&nbsp;<A href="https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcommunity.sap.com%2Ft5%2Ftechnology-q-a%2Fhow-is-bo-impacted-by-log4j-vulnerability%2Fqaq-p%2F12651273&amp;data=05%7C02%7Csoportesbo%40seidor.com%7C660fecbe99d64c393a1b08dc58648d88%7C654623d615044f22a146b7c72637766a%7C0%7C0%7C638482436589599601%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&amp;sdata=DNQxzgWb%2BnFJgXkokvTEkTO7amzXppDt4YScCOHyZiA%3D&amp;reserved=0" target="_blank" rel="noopener nofollow noreferrer">Solved: How is BO impacted by Log4j vulnerability? - SAP Community</A></LI></OL></LI></OL><P>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;i.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;If not using this library file, can it be deleted?</P><OL><LI><STRONG>ASP.NET Core SEoL</STRONG> – The plug in has found multiple EOL version of ASP.NET core including 2.0.13103.0, 2.2.8, 3.1.29<OL><LI>Is SAP using these ASP.NET versions?&nbsp; If so can ASP.NET be upgraded independently of any SAP software (BusinessOne or Business Objects Enterprise)?</LI></OL></LI><LI><STRONG>Microsoft.NET Core SEoL</STRONG> - The plug in has found multiple EOL version of .NET core including 10.16.5115, 1.1.13.1809, 2.0.9.26615, 2.2.8.28209, 3.1.29.31617<OL><LI>Is SAP using these ASP.NET versions?&nbsp; If so can .NET be upgraded independently of any SAP software (BusinessOne or Business Objects Enterprise)?</LI></OL></LI><LI><STRONG>Apache 2.4.x &lt; 2.4.58 Multiple Vulnerabilities</STRONG> – The plug in provides this finding as proof of vulnerability:<OL><LI><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kfumanal_1-1713161615569.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/96414i04DBE1B3237B990B/image-size/medium?v=v2&amp;px=400" role="button" title="kfumanal_1-1713161615569.png" alt="kfumanal_1-1713161615569.png" /></span></LI><LI>Can Apache be upgraded independent of SAP Business One?</LI></OL></LI></OL><P>&nbsp;</P><P>For the first point (Log4j), we have the 3 SAP notes that help us to know the affectation of the vulnerability detected in the following SAP Forum link:</P><P><A href="https://community.sap.com/t5/technology-q-a/how-is-bo-impacted-by-log4j-vulnerability/qaq-p/12651273" target="_blank">https://community.sap.com/t5/technology-q-a/how-is-bo-impacted-by-log4j-vulnerability/qaq-p/12651273</A></P><P>I need to know if there are any specific information regarding points 2, 3 and 4.</P><P>Kind regards,</P> 2024-04-15T08:18:48.701000+02:00 https://community.sap.com/t5/technology-q-a/retire-the-se16-in-production-server/qaq-p/13689109 Retire the SE16 in  Production server 2024-05-02T10:19:22.958000+02:00 SAPSupport https://community.sap.com/t5/user/viewprofilepage/user-id/121003 <P>There is issue with Tx. SE16. Our management want to disable the use of Tx SE16 in Production environment.</P><P>We already restricted through authorization but remove the possibilities for accidental assignment . Please share the possibilities how should we proceed.</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B> 2024-05-02T10:19:22.958000+02:00