SAP Knowledge Base Article - Preview

3775779 - OpenSSL vulnerabilities reported for DP Agent versions delivered with OpenSSL 1.1.1 - SAP HANA Smart Data Integration

Symptom

A vulnerability scan reports OpenSSL vulnerabilities in the DP Agent installation directory. The reported file path points to the OpenSSL binary delivered with the DP Agent, for example:

  • /usr/sap/dataprovagent/ds-lite/bin/openssl

The vulnerability scan result may report one or more of the following CVEs:

  • CVE-2023-0286
  • CVE-2023-0215
  • CVE-2023-0216
  • CVE-2023-0217
  • CVE-2023-0464
  • CVE-2023-0465
  • CVE-2023-0466
  • CVE-2022-3602
  • CVE-2022-3786


Read more...

Environment

  • SAP HANA Smart Data Integration 2.0
  • Data Provisioning Agent versions below 2.8.3.0 

Product

SAP HANA smart data integration 2.0

Keywords

DP Agent, OpenSSL, vulnerability, CVE, CVE-2023-0286, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0464, CVE-2023-0465, CVE-2023-0466, CVE-2022-3602, CVE-2022-3786, security scan, 1.1.1t, 1.1.1zg, OpenSSL 3.0, OpenSSL 3.4.1, ds-lite, openssl.exe, HAN-DP-SDI , KBA , HAN-DP-SDI , SAP HANA smart data integration (SDI) , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.