Patchday January 2022
Patchday January 2022
The first patchday of 2022 is here!
The last patchday in December 2021 was all about the Log4Shell vulnerability. Have you already taken action? If not, you should do so as soon as possible. You can read in the media about possible lawsuits if consumer data is leaked due to these unclosed security vulnerabilities.
Our CEO Jona Ridderskamp warns: "This is one of the most extensive security vulnerabilities we have seen in recent times. I believe that we will not forget this name any time soon. I am very convinced that we will see several large-scale security incidents where companies are facing the end of their existence because of this vulnerability. And I think it's almost impossible to close this gap quickly, consistently and assertively everywhere, because in some cases we don't even know where this gap originates. Because it is in applications that we use that we don't even know are based on Java."
If you need support at this point, please contact us at any time. We help around the clock!
Microsoft
Microsoft released patches for 96 new CVEs in January for Microsoft Windows and Windows components, Microsoft Edge (Chromium-based) Microsoft Office and Office components, Exchange Server, SharePoint Server, Microsoft Dynamics, open source software, Windows Defender and Windows Remote Desktop, Windows Hyper-V, and Protocol (RDP). The patches released earlier this month bring the total number of CVEs to 122.
Of the CVEs patched today, nine are categorised as critical and 89 as severe. Six of these bugs are listed as publicly known, but none are listed as actively under attack.
CVE-2022-21907 HTTP Protocol Stack Remote Code Execution Vulnerability -> This wormable flaw may allow attackers to gain code execution on an affected system. Since the HTTP Protocol Stack (http.sys) is affected, test and patch quickly!
CVE-2022-21840 Microsoft Office Remote Code Execution Vulnerability -> This flaw is classified as critical and there appears to be no warning when a specially crafted file is opened. Several patches are available to fix this bug. Be sure to apply all of them!
CVE-2022-21846 Microsoft Exchange Server Remote Code Execution Vulnerability -> This is another Exchange bug that has been reported by the National Security Agency and has been classified as critical. If attackers manage to connect to the target network and exploit the flaw, they could take over the Exchange server.
CVE-2022-21857 Active Directory Domain Services Elevation of Privilege Vulnerability -> This flaw, which is classified as critical, requires a certain level of privilege. If insiders or attackers get a foot in the network, they could exploit this for lateral movement and maintaining a presence within an organisation.
All CVEs and further information are provided by Zero Day Initiative and the Microsoft Security Response Centre (MSRC) available.
Adobe
Adobe released 5 patches in January that fix 41 CVEs in Acrobat and Reader, Illustrator, Adobe Bridge, InCopy and InDesign. None of these bugs were publicly known at the time of release and were actively under attack.
APSB22-01 : Security update available for Adobe Acrobat and Reader: The security updates for Adobe Acrobat and Reader address several critical, important and moderate vulnerabilities. If successfully exploited, they may lead to arbitrary code execution, memory leaks, denial of service by applications, security feature bypass and privilege escalation.
APSB22-02 : Security update available for Adobe Illustrator: The update for Adobe Illustrator 2021 fixes a critical and a moderate vulnerability. Successful exploitation can lead to an escalation of privileges.
APSB22-03 : Security update available for Adobe Bridge: The security update for Adobe Bridge fixes critical, important and moderate vulnerabilities. These could lead to the execution of arbitrary code and the extension of authorisations.
APSB22-04 : Security update available for Adobe InCopy:The update for Adobe InCopy fixes critical and important security vulnerabilities. It could lead to the execution of arbitrary code and the extension of authorisations.
APSB22-05 : Security update available for Adobe InDesign: An update has been released for Adobe InDesign that fixes critical and moderate security vulnerabilities. If successfully exploited, this can lead to the execution of arbitrary code and the extension of authorisations.
All important information about the vulnerabilities and the necessary downloads can be found at Product Security Incident Response Team (PSIRT) from Adobe.
SAP
SAP published 11 new security advisories and 16 out-of-band in January. There were updates for 3 previously published security advisories.
The security advisories related to the Apache Log4j 2 component are updated on an ongoing basis. SAP advises you to consult the central security notes to obtain the latest information.
[CVE-2021-44228] Central Security Note for Remote Code Execution vulnerability associated with Apache Log4j 2 component -> Consolidated Security Note list (Product: Security Note #) SAP Customer Checkout: 3133772 SAP BTP Cloud Foundry: 3130578 SAP Landscape Management: 3132198 SAP Connected Health Platform 2.0 - Fhirserver: 3131824 SAP HANA XS Advanced Cockpit : 3134531 (includes fix provided in 3131397, 3132822) SAP NetWeaver Process Integration (Java Web Service Adapter) : 3135581 (includes fix provided in 3132204, 3130521, 3133005) SAP HANA XS Advanced : 3131258 Internet of Things Edge Platform : 3132922 SAP BTP Kyma : 3132744 SAP Enable Now Manager : 3132964 SAP Cloud for Customer (add-in for Lotus notes client) : 3132074 SAP Localisation Hub, digital compliance service for India : 3132177 SAP Edge Services On Premise Edition : 3132909 SAP Edge Services Cloud Edition : 3132515 SAP BTP API Management (Tenant Cloning Tool) : 3132162 SAP NetWeaver ABAP Server and ABAP Platform (Adobe LiveCycle Designer 11.0) : 3131691 SAP Digital Manufacturing Cloud for Edge Computing : 3136094 SAP Enterprise Continuous Testing by Tricentis : 3134139 SAP Cloud-to-Cloud Interoperability : 3132058 Reference Template for enabling ingestion and persistence of time series data in Azure : 3136988 SAP Business One : 3131740
[CVE-2022-22531] Multiple vulnerabilities in F0743 Create Single Payment application of SAP S/4HANA Additional CVE - CVE-2022-22530 Product - SAP S/4HANA, Versions - 100, 101, 102, 103, 104, 105, 106
Update to Security Note released on December 2021 Patch Day: [CVE-2021-44235] Code Injection vulnerability in utility class for SAP NetWeaver AS ABAP Product - SAP NetWeaver AS ABAP, Versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756
The SAP Product Security Response Team provides all information on the security notices.
Next patchday is on 08.02.2022. Until then, stay safe and healthy!

Annika Gamerad
Event & Marketing Specialist
Published on 17.05.2025
