SAP security note 2342974, “Arbitrary Valid Certificate Vulnerability in Adobe Document Services”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Adobe Document Services uses an open-source software version – Apache Commons HttpClient 3.x, which has known security vulnerabilities. This version does not verify that the server hostname matches a domain name in the subject’s Common Name (CN) or subjectAltName field of the X.509 certificate. As a result, man-in-the-middle attackers can spoof SSL servers using an arbitrary valid certificate.
Solution
Apply the corresponding Adobe Document Services Support Package (SP) patch.
Reason and prerequisites
This SAP Note is applicable if you are using ADS (Adobe Document Services) on NetWeaver versions 7.30, 7.31, 7.40, or 7.50.
CVSS
Score 6.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
References
- 2567043 – Collective Note: SAP NetWeaver 7.30 SP18 – ADOBE DOCUMENT SERVICES
- 2463608 – Central note for SAP NetWeaver 7.31 SP20/7.40 SP-15 Adobe Document Services
Affected components
- ADSSAP 7.30, 7.31, 7.40, 7.50
Full note on SAP: SAP Support Launchpad note 2342974
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
