SAP security note 2245398, "Java Deserialization Vulnerability in Adobe Interactive Forms", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Adobe Interactive Forms utilizes the open-source Apache Commons Collections library, which contains security vulnerabilities that can lead to arbitrary code execution or denial of service attacks.
This vulnerability poses a significant risk as it allows remote attackers to exploit the system without any authentication or user interaction. The impact includes potential unauthorized access and service disruptions.
Solution
To mitigate this vulnerability, apply the corresponding ADS Support Package (SP) or patch as provided by SAP.
CVSS
Score 7.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
References
- 2528185 – Central Note for ADS NW 7.50 SP-4
- 2120063 – Central Note Adobe Document Services SAP NW 7.3 SPS14
- 2270676 – Collective Note: SAP NetWeaver 7.30 SP15 – Adobe Document Services 7.30
Affected components
- ADS (Adobe Document Services) on NetWeaver versions 7.30, 7.31, 7.40, or 7.50
Full note on SAP: SAP Support Launchpad note 2245398
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
