SAP Knowledge Base Article - Preview

1810721 - Oracle Java Security Alert for CVE-2013-0422

Symptom

On January 13, 2013,  Oracle issued an alert (CVE-2013-0422) confirming a serious security flaw in Java for web browsers.  How does this affect SAP Business Objects Enterprise products?

Excerpt from Oracle CVE-2013-0422:

These vulnerabilities may be remotely exploitable without authentication, i.e., they may be exploited over a network without the need for a username and password. To be successfully exploited, an unsuspecting user running an affected release in a browser will need to visit a malicious web page that leverages these vulnerabilities. Successful exploits can impact the availability, integrity, and confidentiality of the user's system.


Read more...

Environment

Any client web-browser running Oracle Java 7 (JDK and JRE 7 Update 10 and earlier) is affected.

Product

SAP BusinessObjects Business Intelligence platform all versions

Keywords

Oracle, java, vulnerability, flaw, security, exploit, attack, unsigned, CVE-2013-0422 , KBA , BI , Business intelligence solutions , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.