Symptom
- A penetration test reports the Financial Consolidation web HTML5 application uses a third-party component flagged as vulnerable: Moment.js 2.18.1.
- Confirm whether the application uses this component.
- The finding referenced CWE-1104 (use of unmaintained third-party components) without a specific CVE identifier.
Read more...
Environment
- Product: SAP BusinessObjects Financial Consolidation
- Version: 10.1 SP09 Patch 29
- Web HTML5 client
- Technical components: EPM-BFC-UI5, EPM-BFC-TCL
Product
SAP Financial Consolidation 10.1
Keywords
moment.js 2.18.1, html5 web client, financial consolidation, fc 10.1 sp09, third-party library, cwe-1104, penetration test, vulnerable libraries, bundled javascript, epm-bfc-ui5, epm-bfc-tcl, security scan, har capture, impact assessment, web html5 , KBA , EPM-BFC-TCL , Technical Components , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview