SAP Knowledge Base Article - Preview

3471622 - XSA applications deploy-service and product-installer are using affected Spring Framework versions

Symptom

If you have upgrade HANA Cockpit to the version higher than 2.16.10 as per Note 3443879 SAP HANA Cockpit - Spring Framework CVE-2024-22243 Vulnerability, you still found XSA applications deploy-service and product-installer are using the affected Spring Framework versions:

  • 6.1.0 - 6.1.3
  • 6.0.0 - 6.0.16
  • 5.3.0 - 5.3.31


Read more...

Environment

  • SAP HANA extended application services, advanced model (XSA)

Product

SAP HANA, platform edition 2.0

Keywords

 deploy-service, product-installer, CVE-2024-22243, Spring Framework, HANA Cockpit, 2.16.10 , KBA , BC-XS-RT , XS Advanced Runtime / XS Controller , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.