SAP Security Note
High priority
SAP security note 2247644, "PI SEC: Security vulnerabilities found in Apache Groovy Library used in PI Cloud Integration Content", is a program error note released on 12.01.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
PI Cloud Integration Content uses an open source software version for which security vulnerabilities were detected. More details were published in CVE-2015-3253.
Solution
This issue is fixed with the Support Packages and Patches referenced by this SAP Note.
Reason and prerequisites
This SAP Note is only applicable if you are using "Cloud Integration Content" on a Process Integration (PI), Process Orchestration (PO), Adapter Engine, or Adapter Engine Extended (AEX) system.
References
Affected components
- SAP_XIIGW_APPL (from version 7.50 to 7.50)
Full note on SAP: SAP Support Launchpad note 2247644
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
