SAP Security Note
Medium priority
SAP security note 2182488, "Open source vulnerabilities Axis 1.x in SAP EPC 2.0", released on July 31, 2015. Below are the symptom and SAP recommended solution.
Description
Symptom
Apache Axis Version 1.2.1 library used in the SAP Enterprise Project Connection (EPC) 2.0 product is affected by a security vulnerability (CVE-2012-5784).
Solution
Upgrade to a higher version of Apache Axis that is not affected by CVE-2012-5784. This SAP EPC product release includes the necessary fix for this vulnerability.
Reason and prerequisites
The vulnerability arises because Apache Axis version 1.2.1 used in SAP EPC 2.0 does not verify if the server hostname matches a domain name in the subject’s Common Name (CN) or subjectAltName field of the X.509 certificate. This flaw allows man-in-the-middle attackers to spoof SSL servers using an arbitrary valid certificate. For more details, refer to CVE-2012-5784.
References
Full note on SAP: SAP Support Launchpad note 2182488
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
