Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security vulnerabilities found in Apache Commons Collections library used in ep.runtime.common, SAP security note 2249347

SAP Note 2249347

SAP security note 2249347, “Security vulnerabilities found in Apache Commons Collections library used in ep.runtime.common”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

ep.runtime.common utilizes the Apache Commons Collections library, which has been identified to have security vulnerabilities that could lead to arbitrary code execution or denial of service attacks.

The vulnerabilities in the Apache Commons Collections library may allow attackers to execute arbitrary code, cause denial of service, or exploit Java serialization mechanisms.

Solution

To address these vulnerabilities, apply the latest patch provided with this note. You can download the patch for SNOTE here. For a PDF version of this security note, visit PDF Version.

Affected components

  • Enterprise Portal 7.31 SP17
  • Enterprise Portal 7.31 SP1
  • Enterprise Portal 7.40 SP12
  • Enterprise Portal 7.40 SP13
  • Enterprise Portal 7.50 SP0
  • Enterprise Portal 7.50 SP1
  • Enterprise Portal 7.50 SP2

Full note on SAP: SAP Support Launchpad note 2249347

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More