SAP Knowledge Base Article - Preview

3740445 - TLS Robot vulnerability detected on HANA Database Server: Remediation by disabling TLS_RSA ciphers

Symptom

  • TLS ROBOT vulnerability detected on a HANA database by a security scan.
  • Scanner message observed: "ROBOT vulnerability using AES128-SHA with a weak oracle".
  • Related CVEs reported: CVE-2017-6168, CVE-2017-17382, CVE-2017-17427, CVE-2017-17428, CVE-2017-12373, CVE-2017-13098, CVE-2017-1000385, CVE-2017-13099, CVE-2016-6883, CVE-2012-5081

Request for guidance on TLS parameter configuration to remediate.


Read more...

Environment

  • SAP HANA Platform Edition 1.0
  • SAP HANA Platform Edition 2.0

Keywords

TLS ROBOT, ROBOT vulnerability, Bleichenbacher, TLS_RSA, AES128-SHA, sslciphersuites, cipher suites, disable TLS_RSA , KBA , HAN-DB-SEC , SAP HANA Security & User Management , Known Error

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.