Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

Security Note Missing HTTPS support for BPEMUWLConnector, SAP security note 1433737

Description

BPM tasks are not shown in Universal Worklist and there is an error in the Connection Status window next to BPEMUWLConnector saying “Unable to connect…”. This happens in case you have configured communication over HTTPs while configuring the Provider system for BPEMUWLConnector.

Available fix and Supported packages

  • UWLJWF | 7.01 | 7.02
  • UWLJWF | 7.11 | 7.11
  • UWL COLL PROCESS ENGINE 7.01 | SP006 | 000000
  • UWL COLL PROCESS ENGINE 7.02 | SP003 | 000000
  • UWL COLL PROCESS ENGINE 7.11 | SP004 | 000000

Affected component

    BC-BMT-BPM-DSK
    Process Desk

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1433737

TAGS

#Galaxy
#SAP-NW-BPM
#Business-Process-Management
#Universal-Worklist
#BPEMUWLConnector
#HTTPS

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,