SAP Security Note
Medium priority
SAP security note 2504979, "Upgrade SSL support to TLSv1.2", is a program error note released on 10.12.2019. Below are the symptom and SAP recommended solution.
Description
Symptom
Until SP19, MDM supported SSLv3, which was vulnerable to various security issues like the POODLE attack.
Solution
From SP19, MDM supports TLSv1.2 with no option for fallback to SSL. Hence, upgrade to MDM 7.1 SP19 or higher.
- Java API: use JDK 7 or above.
- .NET API: use .NET 4.5 or above.
- WebDynpro or iViews: please follow note 2506562.
CVSS
Score 6.4 Vector: CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
References
Full note on SAP: SAP Support Launchpad note 2504979
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
