Gpg4win vulnerabilities related to BODS

Hello team,

We received vulnerabilities about Gpg4win in BODS systems CVE-2022-3515

We have identified a vulnerability related to the Gpg4win update currently in use on the BODS servers. As confirmed,Gpg4win is installed across these systems.

At present, Gpg4win cannot be upgraded independently, it will be upgrade along with the BODS system upgrade.

Due to this dependency, we are unable to proceed with a standalone remediation of the this vulnerability version at this time..

So our question is please provide us any justification from your side that we can continue with this vulnerabilities?

Thanks,

Roman

Hi Roman

We have neither knowledge of “BODS” nor how you use it.

You can find more information about the specific vulnerability at Security Advisory for Libksba/GnuPG (CVE-2022-3515)

It explains that gpgsm and dirmngr are affected, but not gpg/gpg2.

Further, it states:

In case you are not yet ready to deploy a new version, please extract libksba-8.dll from the respective package and replace the original one by this one. This is sufficient to fix the security issue.

Hopefully, that helps with your remediation.

SAP BODS is a middleware tool used for ETL.BODS production live job is using Gpg4win for extracting the pgp files from source and decrypting it. upgrading it may impact the job and cause operational issue. Due to this dependency, we are unable to proceed with the update.

How can Gpg4win upgraded (as part of BODS)?

(I understand that the BODS system you are using has an old Gpg4win.)
What is the BODS support saying?

I mean we are considering or we want to upgrade Gpg4win along with the BODS upgrade, we dont want to upgrade it now independently

As the version that is deloyed there seems to be a real old version, an upgrade of Gpg4win should be planned (of course). Because there will be other weaknesses that have been found and addresses since then.

(Check out Gpg4win - Change History for an overview.)

As for this specific vulnerability: see the description above. If only OpenPGP is used (e.g. with the executables gpg) and not CMS (as with S/MIME or x509 TLS and so on), then the vulnerability above may not affect the system. (This is standard procedure, if the vulnerability does not affect your system, because it is not used for example, you are not affected. However you should analyse and document the result. Yes, this is extra work, compared to just upgrading. :wink: )

Hope that helps you!