SAP Knowledge Base Article - Preview

3776754 - CVE Vulnerabilities Not Applicable to SAP Commerce Cloud 2211/2205 YForms

Symptom

Background

YForms bundles the commercial third-party library Orbeon Forms, which in turn includes:

  • TinyMCE v6.8.5 — a rich-text editor running in the browser
  • Apache PDFBox 2.0.36 — a PDF processing library (transitively used for HTML-to-PDF rendering via openhtmltopdf)

BlackDuck scans have flagged six CVEs against these libraries. This KBA documents why none of them are applicable to YForms in SAP Commerce Cloud 2211/2205.


Read more...

Environment

SAP Commerce Cloud

Product

SAP Commerce Cloud all versions

Keywords

KBA , CEC-SCC-COM-YFO , yforms , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.