{"id":7502,"date":"2022-03-21T18:56:03","date_gmt":"2022-03-21T16:56:03","guid":{"rendered":"http:\/\/inprosec.com\/?p=7502"},"modified":"2022-03-21T18:56:04","modified_gmt":"2022-03-21T16:56:04","slug":"sap-security-notes-march-2022","status":"publish","type":"post","link":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/","title":{"rendered":"SAP Security Notes, March 2022"},"content":{"rendered":"<p><strong>Inprosec through its services, such as the SAP Security Assessment, helps its customers to improve the security levels of their SAP systems.<\/strong><\/p>\n\n<h2>March 2022 notes<\/h2>\n<h3>Summary and highlights of the month<\/h3>\n<p>The total number of notes\/patches has decreased compared to last month. In addition to this decrease in the total number of notes, the number of Hot News has also decreased, with 9 notes last month compared to 4 in March. On the other hand, it should be noted that the number of high criticality notes decreased from 3 to 1 this month. As usual, we will leave the medium and low scores unchecked this month, but we will give details of a total of 5 scores (all those with a CVSS of 7 or higher).<\/p>\n<p>We have a total of 17 notes for the whole month, 5 less than last February (16 from Patch Tuesday, 12 new and 4 updates, being 6 less than last month).<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>We have 4 critical notes (Hot News), 2 new and 2 updates<\/strong><\/span>, in this month, which stand out for their high CVVS. We will also review in detail 1 of the total of 1 high notes (those with CVSS greater than or equal to 7), which this month is a new note.<\/p>\n<ul>\n<li><strong>The most critical notes of the month (with CVSS <span style=\"color: #ff0000;\">10<\/span>) are 3. On the one hand the central note that affects Apache Log4j 2 component and the note of &#8220;Remote Code Execution vulnerability&#8221; that affects Apache Log4j 2 component used in SAP Work Manager. On the other hand, the third note with this CVSS affects SAP NetWeaver, SAP Content Server and SAP Web Dispatcher.<\/strong><\/li>\n<li>Next in<strong> criticality (CVSS <span style=\"color: #ff0000;\">9.<\/span><span style=\"color: #ff0000;\">3<\/span>)<\/strong> is a &#8220;Missing Authentication check&#8221; note that affects SAP Focused Run.<\/li>\n<li>From there, we locate the high criticality note<strong> (CVSS <span style=\"color: #ff0000;\">8.1<\/span>)<\/strong> of &#8220;Information Disclosure vulnerability&#8221; affecting SAP S\/4HANA. The rest (12) are medium and low level, and we will not see them in detail, although it is worth noting that there is more than one that affects SAP NetWeaver.<\/li>\n<li>This month the most predominant note types are &#8220;Cross-Site Scripting (XSS)&#8221; (4\/17 and 4\/16 on patch day), &#8220;Missing Authorization Check&#8221; (3\/17 and 3\/16 on patch day) and &#8220;Information Disclosure&#8221; (3\/17 and 3\/16 on patch day).<\/li>\n<\/ul>\n<p>In the graph (post March 2022 from SAP) we can see the <span style=\"text-decoration: underline;\"><strong>ranking of the March notes<\/strong><\/span> in addition to the evolution and ranking of the last 5 previous months (only the notes of Sec. Tuesday \/ Patch Day &#8211; by SAP):<\/p>\n<p><img decoding=\"async\" class=\"aligncenter  wp-image-7506\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2022\/03\/notas-marzo-1.jpg\" alt=\"\" width=\"899\" height=\"471\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2022\/03\/notas-marzo-1.jpg 1200w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2022\/03\/notas-marzo-1-300x157.jpg 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2022\/03\/notas-marzo-1-1024x536.jpg 1024w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2022\/03\/notas-marzo-1-600x314.jpg 600w\" sizes=\"(max-width: 899px) 100vw, 899px\" \/><\/p>\n<h3>Full details<\/h3>\n<p>The<span style=\"text-decoration: underline;\"><strong> full details of the most relevant notes<\/strong><\/span> are as follows:<\/p>\n<ul>\n<li><strong><u>Update &#8211; Central Security Note for Remote Code Execution vulnerability associated with Apache Log4j 2 component (3131047):<\/u><\/strong> It is the central SAP Security Note for the Log4j vulnerability and was updated with information about the new note #3154684. <strong>CVSS v3 Base Score: <span style=\"color: #ff0000;\">10<\/span> \/ 10<\/strong> (CVE-2021-44228).<\/li>\n<li><strong><u>Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Work Manager (3154684):<\/u><\/strong> It affects the SAP Work Manager and SAP Inventory application. Both applications run on SAP Mobile Platform (SMP) and only on-premise installations of the SMP are affected. The note recommends upgrading to SAP Work Manager 6.6.1 and\/or SAP Inventory Manager 4.4.1 since\u00a0 these application versions were built with the new library versions of the log4j library. As a workaround, a direct replacement of the vulnerable log4j library on the SMP server can be implemented. Due to the fact that SAP Work Manager versions prior to 6.4 do not use log4j libraries, they are not affected by the Log4j vulnerabilities. <strong>CVSS v3 Base Score: <span style=\"color: #ff0000;\">10<\/span> \/ 10<\/strong> (CVE-2021-44228).<\/li>\n<li><strong><u>Update &#8211; Request smuggling and request concatenation in SAP NetWeaver, SAP Content Server and SAP Web Dispatcher (3123396):<\/u><\/strong> Update that was initially released on February\u2019s Patch Day. It contains some additional information, including a reference to the Knowledge Base Article #3148968 which contains an FAQ about the patch. <strong>CVSS v3 Base Score: <span style=\"color: #ff0000;\">10<\/span> \/ 10<\/strong> (CVE-2022-22536).<\/li>\n<li><strong><u>Missing Authentication check in SAP Focused Run (Simple Diagnostics Agent 1\/0) (3145987):<\/u><\/strong> It patches a Missing Authentication vulnerability in the SAP Simple Diagnostics Agent. This agent is installed and deployed as an add-on to the SAP Host Agent and it is a prerequisite for using the Simple System Integration (SSI) in SAP Focused Run.<strong> CVSS v3 Base Score: <span style=\"color: #ff0000;\">9.3<\/span> \/ 10<\/strong> (CVE-2022-24396).<\/li>\n<li><strong><u>Cross-Site Scripting (XSS) vulnerability in SAP Fiori launchpad (3149805):<\/u><\/strong> It patches a Cross-Site Scripting (XSS) vulnerability in SAP Fiori launchpad. Our research team detected that SAP Fiori launchpad allows an unauthenticated attacker to manipulate the SAP-theme URL parameter \u2014\u00a0 and inject HTML code \u2014 and create a link over the network for a user to click on. Once the link is clicked, successful exploitation allows the attacker to hijack user privileges that can be used to exfiltrate data and craft a CSRF attack to manipulate data. This can limit the application\u2019s confidentiality and pose risks to its integrity, as well as increase the likelihood of it being completely compromised.<strong> CVSS v3 Base Score: <span style=\"color: #ff0000;\">8.1<\/span> \/ 10<\/strong> (CVE-2022-26101).<\/li>\n<\/ul>\n<h3 style=\"font-weight: 400;\"><strong>Reference links<\/strong><\/h3>\n<p>Reference links of the CERT of the INCIBE in relation to the publication of the notes for March:<\/p>\n<p><a href=\"https:\/\/www.incibe-cert.es\/alerta-temprana\/avisos-seguridad\/actualizacion-seguridad-sap-marzo-2022\">https:\/\/www.incibe-cert.es\/alerta-temprana\/avisos-seguridad\/actualizacion-seguridad-sap-marzo-2022<\/a><\/p>\n<p>Other references, from SAP and Onapsis (March):<\/p>\n<p><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10<\/a><\/p>\n<p><a href=\"https:\/\/onapsis.com\/blog\/sap-security-patch-day-march-2022-sap-focused-run-affected-several-vulnerabilities\">https:\/\/onapsis.com\/blog\/sap-security-patch-day-march-2022-sap-focused-run-affected-several-vulnerabilities<\/a><\/p>\n<h3 style=\"font-weight: 400;\"><strong><u>Resources affected<\/u><\/strong><\/h3>\n<ul>\n<li>Fiori Launchpad, versiones: 754, 755 y 756;<\/li>\n<li>SAP Business Objects Business Intelligence Platform, versiones 420 y 430;<\/li>\n<li>SAP Content Server, versi\u00f3n 7.53;<\/li>\n<li>SAP Financial Consolidation, versi\u00f3n 10.1;<\/li>\n<li>SAP Focused Run, versiones: 200 y 300;<\/li>\n<li>SAP Inventory Manager, versiones: 4.3 y 4.4;<\/li>\n<li>SAP NetWeaver and ABAP Platform, versiones: KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, KRNL64UC 8.04, 7.22, 7.22EXT, 7.49, 7.53, KRNL64NUC 7.22, 7.22EXT y 7.4;<\/li>\n<li>SAP NetWeaver:<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Application Server for ABAP, versiones: 700, 701, 702 y 731;<\/li>\n<li>AS JAVA (Portal Basis), versi\u00f3n 7.50;<\/li>\n<li>Enterprise Portal, versiones: 7.10, 7.11, 7.20, 7.30, 7.31, 7.40 y 7.50;<\/li>\n<\/ul>\n<\/li>\n<li>SAP Web Dispatcher, versiones: 7.49, 7.53, 7.77, 7.81, 7.85, 7.22EXT, 7.86 y 7.87;<\/li>\n<li>SAP Work Manager, versiones: 6.4, 6.5 y 6.6;<\/li>\n<li>SAPCAR, versi\u00f3n 7.22;<\/li>\n<li>SAP-JEE, versi\u00f3n 6.40;<\/li>\n<li>SAP-JEECOR, versiones: 6.40, 7.00 y 7.01;<\/li>\n<li>SAPS\/4HANA (Hoja de datos de proveedores y b\u00fasqueda de empresas para socios comerciales, proveedores y clientes), versiones: 104, 105 y 106;<\/li>\n<li>SERVERCORE, versiones: 7.10, 7.11, 7.20, 7.30 y 7.31;<\/li>\n<li>Simple Diagnostics Agent, versiones: =&gt;1.0 a &lt; 1.58.<\/li>\n<li>Simple Diagnostics Agent;<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Inprosec through its services, such as the SAP Security Assessment, helps its customers to improve the security levels of their SAP systems. March 2022 notes Summary and highlights of the month The total number of notes\/patches has decreased compared to last month. In addition to this decrease in the total number of notes, the number&#8230;<\/p>\n","protected":false},"author":6,"featured_media":7506,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[61],"tags":[],"class_list":["post-7502","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sap-security-en-2"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.3 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>SAP Security Notes, March 2022 - Inprosec<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SAP Security Notes, March 2022\" \/>\n<meta property=\"og:description\" content=\"Inprosec through its services, such as the SAP Security Assessment, helps its customers to improve the security levels of their SAP systems. March 2022 notes Summary and highlights of the month The total number of notes\/patches has decreased compared to last month. In addition to this decrease in the total number of notes, the number...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/\" \/>\n<meta property=\"og:site_name\" content=\"Inprosec\" \/>\n<meta property=\"article:published_time\" content=\"2022-03-21T16:56:03+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-03-21T16:56:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2022\/03\/notas-marzo-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Fernando Mosquera\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Fernando Mosquera\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2022\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2022\\\/\"},\"author\":{\"name\":\"Fernando Mosquera\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"headline\":\"SAP Security Notes, March 2022\",\"datePublished\":\"2022-03-21T16:56:03+00:00\",\"dateModified\":\"2022-03-21T16:56:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2022\\\/\"},\"wordCount\":967,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2022\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/notas-marzo-1.jpg\",\"articleSection\":[\"SAP Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2022\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2022\\\/\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2022\\\/\",\"name\":\"SAP Security Notes, March 2022 - Inprosec\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2022\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2022\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/notas-marzo-1.jpg\",\"datePublished\":\"2022-03-21T16:56:03+00:00\",\"dateModified\":\"2022-03-21T16:56:04+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2022\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2022\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2022\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/notas-marzo-1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/notas-marzo-1.jpg\",\"width\":1200,\"height\":628},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-march-2022\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SAP Security Notes, March 2022\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\",\"name\":\"Inprosec\",\"description\":\"Information security is our priority.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\",\"name\":\"Fernando Mosquera\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"caption\":\"Fernando Mosquera\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SAP Security Notes, March 2022 - Inprosec","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/","og_locale":"en_US","og_type":"article","og_title":"SAP Security Notes, March 2022","og_description":"Inprosec through its services, such as the SAP Security Assessment, helps its customers to improve the security levels of their SAP systems. March 2022 notes Summary and highlights of the month The total number of notes\/patches has decreased compared to last month. In addition to this decrease in the total number of notes, the number...","og_url":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/","og_site_name":"Inprosec","article_published_time":"2022-03-21T16:56:03+00:00","article_modified_time":"2022-03-21T16:56:04+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2022\/03\/notas-marzo-1.jpg","type":"image\/jpeg"}],"author":"Fernando Mosquera","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Fernando Mosquera","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/#article","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/"},"author":{"name":"Fernando Mosquera","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"headline":"SAP Security Notes, March 2022","datePublished":"2022-03-21T16:56:03+00:00","dateModified":"2022-03-21T16:56:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/"},"wordCount":967,"commentCount":0,"image":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2022\/03\/notas-marzo-1.jpg","articleSection":["SAP Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/","url":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/","name":"SAP Security Notes, March 2022 - Inprosec","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/#primaryimage"},"image":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2022\/03\/notas-marzo-1.jpg","datePublished":"2022-03-21T16:56:03+00:00","dateModified":"2022-03-21T16:56:04+00:00","author":{"@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"breadcrumb":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/#primaryimage","url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2022\/03\/notas-marzo-1.jpg","contentUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2022\/03\/notas-marzo-1.jpg","width":1200,"height":628},{"@type":"BreadcrumbList","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-march-2022\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.inprosec.com\/en\/"},{"@type":"ListItem","position":2,"name":"SAP Security Notes, March 2022"}]},{"@type":"WebSite","@id":"https:\/\/www.inprosec.com\/en\/#website","url":"https:\/\/www.inprosec.com\/en\/","name":"Inprosec","description":"Information security is our priority.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.inprosec.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2","name":"Fernando Mosquera","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","caption":"Fernando Mosquera"}}]}},"_links":{"self":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/7502","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/comments?post=7502"}],"version-history":[{"count":2,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/7502\/revisions"}],"predecessor-version":[{"id":7509,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/7502\/revisions\/7509"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media\/7506"}],"wp:attachment":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media?parent=7502"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/categories?post=7502"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/tags?post=7502"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}