SAP Business Intelligence and the OpenSSL “Heartbleed” vulnerability
maybe you are already aware of the critical security issue within the Open Source implementation of SSL called OpenSSL.
There is a critical Vulnerability that grants an attacker access to the Stream of Data between the Client and the Server even if the attacker has recorded the whole Data stream of the last two years (It has gone public that this critical issue is in the OpenSSL implementation for two years now). This is possible via 64 kb small “Ping” signal that travels between the Client and the Server to check if the connection still active. This “Ping” can be compromised to read the Private Key out of the Server Memory.
For more Information please check the following Web Site:
SAP BusinessObjects Enterprise XI 3.x is not affected from this Bug as it is using the older OpenSSL Libraries in the Version 0.9.8.
SAP Business Intelligence Platform 4.x is not affected from this Bug at is is using the RSA implementation of SSL.
OpenSSL Libraries in the Version 1.0.1 and 1.0.1f are effected.
SAP created the following Note for more information: