We received vulnerabilities about Gpg4win in BODS systems CVE-2022-3515
We have identified a vulnerability related to the Gpg4win update currently in use on the BODS servers. As confirmed,Gpg4win is installed across these systems.
At present, Gpg4win cannot be upgraded independently, it will be upgrade along with the BODS system upgrade.
Due to this dependency, we are unable to proceed with a standalone remediation of the this vulnerability version at this time..
So our question is please provide us any justification from your side that we can continue with this vulnerabilities?
It explains that gpgsm and dirmngr are affected, but not gpg/gpg2.
Further, it states:
In case you are not yet ready to deploy a new version, please extract libksba-8.dll from the respective package and replace the original one by this one. This is sufficient to fix the security issue.
SAP BODS is a middleware tool used for ETL.BODS production live job is using Gpg4win for extracting the pgp files from source and decrypting it. upgrading it may impact the job and cause operational issue. Due to this dependency, we are unable to proceed with the update.
As the version that is deloyed there seems to be a real old version, an upgrade of Gpg4win should be planned (of course). Because there will be other weaknesses that have been found and addresses since then.
As for this specific vulnerability: see the description above. If only OpenPGP is used (e.g. with the executables gpg) and not CMS (as with S/MIME or x509 TLS and so on), then the vulnerability above may not affect the system. (This is standard procedure, if the vulnerability does not affect your system, because it is not used for example, you are not affected. However you should analyse and document the result. Yes, this is extra work, compared to just upgrading. )