SAP Knowledge Base Article - Preview

3737747 - Applicability for CVE‑2024‑28752 (Apache CXF SSRF) in PI/PO 7.50 SP28

Symptom

- The applicability of CVE-2024-28752 (Apache CXF SSRF) to SAP PI/PO 7.50 SP28. 
- The issue involves a security vulnerability reported by enterprise security scanning tools against the SAP-delivered Apache CXF library (org.apache.cxf-cxf-core-3.2.11-sap-05.jar).
- queries include whether the vulnerability is applicable to SAP PI/PO 7.50 SP28, whether the Apache CXF Aegis DataBinding is used or exposed in standard configurations, and whether SAP has backported fixes or mitigated the issue.


Read more...

Environment

Product version: SAP NetWeaver 7.5 

Product

SAP NetWeaver 7.5

Keywords

 CVE‑2024‑28752, vulnerability, Apache CXF , KBA , BC-XI-IGW , Integration Gateway , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.