Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Java Deserialization Vulnerability in Adobe Interactive Forms, SAP security note 2245398

SAP Note 2245398

SAP security note 2245398, "Java Deserialization Vulnerability in Adobe Interactive Forms", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Adobe Interactive Forms utilizes the open-source Apache Commons Collections library, which contains security vulnerabilities that can lead to arbitrary code execution or denial of service attacks.

This vulnerability poses a significant risk as it allows remote attackers to exploit the system without any authentication or user interaction. The impact includes potential unauthorized access and service disruptions.

Solution

To mitigate this vulnerability, apply the corresponding ADS Support Package (SP) or patch as provided by SAP.

CVSS

Score 7.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

References

Affected components

  • ADS (Adobe Document Services) on NetWeaver versions 7.30, 7.31, 7.40, or 7.50

Full note on SAP: SAP Support Launchpad note 2245398

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More