Archive - 2022

1
SAP Security Notes Summary – February 2022
2
How to Enable TLS v1.2 in SAP Netweaver ABAP
3
SAP Solution Manager 7.2 – EarlyWatch Alerts
4
SAP Solution Manager 7.2 – problem with Automatic Distribution of License Data
5
[CVE-2022-22536] – major vulnerability in SAP NetWeaver, SAP Content Server and SAP Web Dispatcher
6
Mass Changes of Jobs in ABAP environment

How to Enable TLS v1.2 in SAP Netweaver ABAP

In this article we’ll go through the process of enabling TLS v1.2 in SAP Netweaver ABAP system. At the beginning I have to mention about CommonCryptoLib (CCL) which many years ago replaced the SAPCRYPTOLIB. The new SAP Cryptographic Library not only supports the use of digital signatures in SAP Systems, but also provides for encryption. The CCL is available in its latest version 8.5.x and is used by many SAP components. Some examples are:

  • SAP Host Agent,
  • SAP Instance Agent,
  • SAP NetWeaver AS ABAP,
  • SAP NetWeaver AS Java,
  • SAP HANA,
  • SAP Web Dispatcher,
  • etc.
Read More

SAP Solution Manager 7.2 – EarlyWatch Alerts

SAP EarlyWatch Alert (EWA) is an automatic service analyzing the essential administrative areas of an SAP system. Alerts indicate critical situations and give solutions to improve performance and stability. To check and display these alerts in the corresponding reports, SAP offers the SAP EarlyWatch Alert Workspace in the SAP ONE Support Launchpad and also automaticaly generated reports for SAP Solution Manager 7.2.

Read More

SAP Solution Manager 7.2 – problem with Automatic Distribution of License Data

In last year I wrote about Automatic Distribution of License Data in Solman 7.2 – check here. Today an example from real life. According to You

  • the configuration looks good,
  • job: “REFRESH_ADMIN_DATA_FROM_SUPPORT” and SDCCN procedure (GET LICENSE) are fulfilling,
  • the system number (18 digits) is correct in LMDB for Your satelite systems,
Read More

[CVE-2022-22536] – major vulnerability in SAP NetWeaver, SAP Content Server and SAP Web Dispatcher

It’s new (08.02.2022) and very important issue becasue CVSS score is 10 (critical). An unauthenticated attacker can prepend a victim’s request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack  could result in complete compromise of Confidentiality, Integrity and Availability of the system.

Read More

Copyright © 2026. SAPBasisWorld.com Privacy Policy