SAP Knowledge Base Article - Preview

3764888 - SAP FC vulnerability CVE-2014-5455

Symptom

  • Request to confirm whether the product is affected by the CVE-2014-5455.
  • CVE-2014-5455 An Unquoted Windows Search Path vulnerability affecting PrivateTunnel prior to version 3.0 and OpenVPN Connect prior to version 3.1 on Windows. The vulnerable service (ptservice) may execute an attacker-controlled executable if the service path contains spaces and lacks quotation marks, allowing a local privilege escalation scenario.


Read more...

Environment

  • SAP BusinessObjects Financial Consolidation (FC) 10.1.

Product

SAP Financial Consolidation 10.1

Keywords

cve-2014-5455, security vulnerability, vulnerability assessment, financial consolidation, not impacted, components not used, bfc, epm-bfc, product security, cve impact, mitigation, workaround, confirmation , KBA , EPM-BFC-PSI , Performance, Stability, Installation , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.