Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Open source vulnerabilities Axis 1.x in SAP EPC 2.0, SAP security note 2182488

SAP Note 2182488
SAP Security Note
Medium priority

SAP security note 2182488, "Open source vulnerabilities Axis 1.x in SAP EPC 2.0", released on July 31, 2015. Below are the symptom and SAP recommended solution.

ComponentCross-Application Components > Enterprise Project Connection (CA-EPC)
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onJuly 31, 2015

Description

Symptom

Apache Axis Version 1.2.1 library used in the SAP Enterprise Project Connection (EPC) 2.0 product is affected by a security vulnerability (CVE-2012-5784).

Solution

Upgrade to a higher version of Apache Axis that is not affected by CVE-2012-5784. This SAP EPC product release includes the necessary fix for this vulnerability.

Reason and prerequisites

The vulnerability arises because Apache Axis version 1.2.1 used in SAP EPC 2.0 does not verify if the server hostname matches a domain name in the subject’s Common Name (CN) or subjectAltName field of the X.509 certificate. This flaw allows man-in-the-middle attackers to spoof SSL servers using an arbitrary valid certificate. For more details, refer to CVE-2012-5784.

References

Full note on SAP: SAP Support Launchpad note 2182488

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More