Skip to Content
Author's profile photo Sebastian Wiefett

SAP Business Intelligence and the OpenSSL “Heartbleed” vulnerability

Hello everyone,

maybe you are already aware of the critical security issue within the Open Source implementation of SSL called OpenSSL.

There is a critical Vulnerability that grants an attacker access to the Stream of Data between the Client and the Server even if the attacker has recorded the whole Data stream of the last two years (It has gone public that this critical issue is in the OpenSSL implementation for two years now). This is possible via 64 kb small “Ping” signal that travels between the Client and the Server to check if the connection still active. This “Ping” can be compromised to read the Private Key out of the Server Memory.

For more Information please check the following Web Site:

Heartbleed Bug

SAP BusinessObjects Enterprise XI 3.x is not affected from this Bug as it is using the older OpenSSL Libraries in the Version 0.9.8.

SAP Business Intelligence Platform 4.x is not affected from this Bug at is is using the RSA implementation of SSL.

OpenSSL Libraries in the Version 1.0.1 and 1.0.1f are effected.

SAP created the following Note for more information:

http://service.sap.com/sap/support/notes/2003582

Regards

-Seb.

Assigned Tags

      2 Comments
      You must be Logged on to comment or reply to a post.
      Author's profile photo Former Member
      Former Member

      Hi.

      Do you know if there is a corresponding note for SAP PI regarding the Heartbleed bug?

      Author's profile photo Sebastian Wiefett
      Sebastian Wiefett
      Blog Post Author

      Hello Anna,

      currently the PSRT Team of SAP (Product Security Response Team) is investigating the Heardbleed issue with all SAP Products. You can wait for this statement or otherwise create an Incident with the SAP Support to get the latest information for your SAP Products in this manner.

      Regards

      -Seb.