<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAP AS Java affected from commons-collection vulnerability? in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409700#M1925839</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Especially &lt;A href="http://service.sap.com/sap/support/notes/2246851" title="http://service.sap.com/sap/support/notes/2246851"&gt;http://service.sap.com/sap/support/notes/2246851&lt;/A&gt; seems to be relevant for PI, maybe this one for Wily, too &lt;A href="http://service.sap.com/sap/support/notes/2262104" title="http://service.sap.com/sap/support/notes/2262104"&gt;http://service.sap.com/sap/support/notes/2262104&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Feb 2016 13:20:32 GMT</pubDate>
    <dc:creator>JaySchwendemann</dc:creator>
    <dc:date>2016-02-17T13:20:32Z</dc:date>
    <item>
      <title>SAP AS Java affected from commons-collection vulnerability?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409694#M1925833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we are running an PI AEX (AS Netweaver Java 7.4) and I recently heard about this vulnerability: &lt;A href="http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/" title="http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/"&gt;What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnerability. | &lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a quick search in the Java Class Loader View from PIs NWA and did not find any Apache Library there. But as I would consider myself far from a J2EE expert I might easily looking in the wrong place.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my questions are:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Do you know if the SAP Netweaver AS Java might be affected&lt;/LI&gt;&lt;LI&gt;How should I check, e.g. where to do that "grep" the above link mentioned&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks and kind regards&lt;/P&gt;&lt;P&gt;Jens&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Nov 2015 10:23:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409694#M1925833</guid>
      <dc:creator>JaySchwendemann</dc:creator>
      <dc:date>2015-11-11T10:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: SAP AS Java affected from commons-collection vulnerability?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409695#M1925834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hi, Jens!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you received any confirmation for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Aleksi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Nov 2015 14:49:20 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409695#M1925834</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2015-11-23T14:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: SAP AS Java affected from commons-collection vulnerability?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409696#M1925835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, unfortunately not. Considering opening an incident for this to get some information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will keep this thread updated then.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anybody else has information about this, please feel free to add here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Jens&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Nov 2015 11:06:37 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409696#M1925835</guid>
      <dc:creator>JaySchwendemann</dc:creator>
      <dc:date>2015-11-26T11:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: SAP AS Java affected from commons-collection vulnerability?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409697#M1925836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP has provided the following reply:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"SAP has received information about security deficiencies in some java&lt;/P&gt;&lt;P&gt;classes used in deserialization, used in a number of software products&lt;/P&gt;&lt;P&gt;of different vendors. These deficiencies are referred to under the&lt;/P&gt;&lt;P&gt;name of "java deserialization vulnerability#. Currently, this&lt;/P&gt;&lt;P&gt;vulnerability has been identified in some of the commonly used open&lt;/P&gt;&lt;P&gt;source libraries (Apache Groovy [CVE-2015-3253] and Apache Commons&lt;/P&gt;&lt;P&gt;Collections). SAP security teams are in the process of investigating&lt;/P&gt;&lt;P&gt;if SAP products are affected by the reported vulnerability.&lt;/P&gt;&lt;P&gt;&amp;nbsp; SAP takes any security-related report very seriously. We will notify&lt;/P&gt;&lt;P&gt;our customers appropriately as relevant new information on this topic&lt;/P&gt;&lt;P&gt;becomes available.&lt;/P&gt;&lt;P&gt;&amp;nbsp; We take the opportunity to remind you to increase the security of&lt;/P&gt;&lt;P&gt;your SAP systems by installing the available security patches.&lt;/P&gt;&lt;P&gt;For information on SAP's security notes and patches, please refer to -&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://support.sap.com/securitynotes"&gt;https://support.sap.com/securitynotes&lt;/A&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Aleksi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Nov 2015 11:12:17 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409697#M1925836</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2015-11-26T11:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: SAP AS Java affected from commons-collection vulnerability?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409698#M1925837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great, thanks for sharing. Would be great if you update this thread if SAP is directly updating you with some information (maybe you opened an incident for this?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyways we'll have to wait and see the outcome of this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Jens&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Nov 2015 11:50:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409698#M1925837</guid>
      <dc:creator>JaySchwendemann</dc:creator>
      <dc:date>2015-11-26T11:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: SAP AS Java affected from commons-collection vulnerability?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409699#M1925838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some SAP Notes have already been released related to this. Please search for "java serialization vulnerability".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Aleksi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jan 2016 12:14:36 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409699#M1925838</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2016-01-14T12:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: SAP AS Java affected from commons-collection vulnerability?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409700#M1925839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Especially &lt;A href="http://service.sap.com/sap/support/notes/2246851" title="http://service.sap.com/sap/support/notes/2246851"&gt;http://service.sap.com/sap/support/notes/2246851&lt;/A&gt; seems to be relevant for PI, maybe this one for Wily, too &lt;A href="http://service.sap.com/sap/support/notes/2262104" title="http://service.sap.com/sap/support/notes/2262104"&gt;http://service.sap.com/sap/support/notes/2262104&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Feb 2016 13:20:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-affected-from-commons-collection-vulnerability/m-p/11409700#M1925839</guid>
      <dc:creator>JaySchwendemann</dc:creator>
      <dc:date>2016-02-17T13:20:32Z</dc:date>
    </item>
  </channel>
</rss>

