PT-2024-3863 · Sap · Sap Cloud Connector

Fabian Hagg

+1

·

Published

2024-02-12

·

Updated

2024-10-16

·

CVE-2024-25642

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP Cloud Connector version 2.0
Description The issue is related to improper validation of certificates in SAP Cloud Connector, allowing an attacker to impersonate genuine servers and break mutual authentication. This can lead to the interception of requests, potentially allowing the viewing or modification of sensitive information. The vulnerability affects the confidentiality and integrity of protected information, but there is no impact on system availability.
Recommendations For SAP Cloud Connector version 2.0, update the software to a version that properly validates certificates, ensuring mutual authentication is maintained to prevent impersonation attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2024-04264
CVE-2024-25642

Affected Products

Sap Cloud Connector