CVE-2024-25642: Improper Certificate Validation in SAP Cloud Connector
Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the mutual authentication. Hence, the attacker can intercept the request to view/modify sensitive information. There is no impact on the availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25642?
CVE-2024-25642 has a high severity due to the potential for an attacker to impersonate servers and intercept sensitive information.
How do I fix CVE-2024-25642?
To fix CVE-2024-25642, ensure that your SAP Cloud Connector version is updated to the latest secure version that addresses the certificate validation issue.
What systems are affected by CVE-2024-25642?
CVE-2024-25642 specifically affects SAP Cloud Connector version 2.0.
What type of attack can be executed due to CVE-2024-25642?
An attacker can perform a man-in-the-middle attack by impersonating genuine servers due to improper certificate validation.
What are the risks associated with CVE-2024-25642?
The risks associated with CVE-2024-25642 include unauthorized access to sensitive data and the ability to modify requests sent to the SAP Cloud Connector.