SAP Knowledge Base Article - Preview

2004903 - OpenSSL Vulnerability (Heartbleed bug) for SAP Afaria

Symptom

Products packaged with OpenSSL 1.0.1 through 1.0.1f (inclusive) are vulnerable, which leads to this informational disclosure.

As of version 7.0 Service Pack 4(SP4), SAP Afaria uses the OpenSSL libraries in the XSRedirector component. Versions of SAP Afaria prior to 7.0 SP4 are not impacted because the XSRedirector did not use OpenSSL libraries in those releases.


Read more...

Environment

SAP Afaria 7.0 SP4

Product

SAP Afaria 7.0

Keywords

Information disclosure, Open SSL vulnerability, Heartbleed bug, CVE-2014-0160, Sybase Afaria, relay server, rsoe, certificates, 509, x.509, XNET, XNETS, HTTP, 1.0.1g, 1.0.1e , KBA , openssl , heartbleed , cve-2014-0160 , MOB-AFA , Afaria , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.