<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Vulernabilities in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/vulernabilities/m-p/12198809#M1981581</link>
    <description>&lt;P&gt;Is there a version of the crystal reports runtime installer that addresses the following vulnerabilities:&lt;/P&gt;
  &lt;UL&gt; 
   &lt;LI&gt;1.Vulnerabilities exist because CRRuntime installs IIS to the root of C:\. This is considered a high vulnerability. &lt;/LI&gt;
   &lt;LI&gt;This can be found in the following locations within the application:&lt;/LI&gt;
   &lt;LI&gt;C:\inetpub&lt;/LI&gt;
   &lt;LI&gt;2.Vulnerabilities exist because CRRuntime installs an &lt;STRONG&gt;unknown version of libcurl&lt;/STRONG&gt; which may contain vulnerabilities according to the following Common Vulnerabilities datastore link:&lt;/LI&gt;
   &lt;LI&gt;&lt;A href="https://www.cvedetails.com/vulnerability-list/vendor_id-12682/product_id-25085/Haxx-Libcurl.html" target="test_blank"&gt;https://www.cvedetails.com/vulnerability-list/vendor_id-12682/product_id-25085/Haxx-Libcurl.html&lt;/A&gt; &lt;/LI&gt;
  &lt;/UL&gt;
  &lt;UL&gt; 
   &lt;LI&gt;This can be found in the following location within the application: c:\program files (x86)\sap businessobjects\crystal reports for .net framework 4.0\common\sap businessobjects enterprise xi 4.0\win32_x86\libcurl.dll &lt;/LI&gt;
   &lt;LI&gt;3.Vulnerabilities exist because CRRuntime installs libssh2 version 1.4.3 which contain vulnerabilities according to the following Common Vulnerabilities datastore link:&lt;/LI&gt; 
  &lt;/UL&gt;
  &lt;A href="https://www.cvedetails.com/vulnerability-list/vendor_id-15300/product_id-31293/Libssh2-Libssh2.html"&gt;https://www.cvedetails.com/vulnerability-list/vendor_id-15300/product_id-31293/Libssh2-Libssh2.html&lt;/A&gt;
  &lt;BR /&gt;
  &lt;UL&gt;
   &lt;LI&gt;This can be found in the following location within the application:c:\program files (x86)\sap businessobjects\crystal reports for .net framework 4.0\common\sap businessobjects enterprise xi 4.0\win32_x86\libssh2.dll&lt;/LI&gt;
  &lt;/UL&gt;
  &lt;LI&gt;4.Vulnerabilities exist because CRRuntime installs openssl version 1.0.2h which contain vulnerabilities according to the following Common Vulnerabilities datastore link:&lt;/LI&gt; 
  &lt;A href="https://www.cvedetails.com/vulnerability-list/vendor_id-217/product_id-383/Openssl-Openssl.html"&gt;https://www.cvedetails.com/vulnerability-list/vendor_id-217/product_id-383/Openssl-Openssl.html&lt;/A&gt;
  &lt;BR /&gt; 
  &lt;UL&gt;
   &lt;LI&gt;This can be found in the following location within the application: c:\program files (x86)\sap businessobjects\crystal reports for .net framework 4.0\common\sap businessobjects enterprise xi 4.0\win32_x86\ssleaym32.dll&lt;/LI&gt;
  &lt;/UL&gt;
  &lt;LI&gt;5.Vulnerabilities exist because Arena Simulation version 16.x installs xercex version 3.1.4 which contain vulnerabilities according to the following Common Vulnerabilities datastore link:&lt;/LI&gt; 
  &lt;A href="https://www.cvedetails.com/vulnerability-list/vendor_id-45/product_id-31348/Apache-Xerces-c.html"&gt;https://www.cvedetails.com/vulnerability-list/vendor_id-45/product_id-31348/Apache-Xerces-c.html&lt;/A&gt;
  &lt;BR /&gt; 
  &lt;BR /&gt; 
  &lt;UL&gt;
   &lt;LI&gt;This can be found in the following location within the application: c:\program files (x86)\sap businessobjects\crystal reports for .net framework 4.0\common\sap businessobjects enterprise xi 4.0\win32_x86\xerces-c_3_1.dll&lt;/LI&gt;
  &lt;/UL&gt; 
  &lt;BR /&gt;</description>
    <pubDate>Mon, 16 Mar 2020 14:35:25 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2020-03-16T14:35:25Z</dc:date>
    <item>
      <title>Vulernabilities</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/vulernabilities/m-p/12198809#M1981581</link>
      <description>&lt;P&gt;Is there a version of the crystal reports runtime installer that addresses the following vulnerabilities:&lt;/P&gt;
  &lt;UL&gt; 
   &lt;LI&gt;1.Vulnerabilities exist because CRRuntime installs IIS to the root of C:\. This is considered a high vulnerability. &lt;/LI&gt;
   &lt;LI&gt;This can be found in the following locations within the application:&lt;/LI&gt;
   &lt;LI&gt;C:\inetpub&lt;/LI&gt;
   &lt;LI&gt;2.Vulnerabilities exist because CRRuntime installs an &lt;STRONG&gt;unknown version of libcurl&lt;/STRONG&gt; which may contain vulnerabilities according to the following Common Vulnerabilities datastore link:&lt;/LI&gt;
   &lt;LI&gt;&lt;A href="https://www.cvedetails.com/vulnerability-list/vendor_id-12682/product_id-25085/Haxx-Libcurl.html" target="test_blank"&gt;https://www.cvedetails.com/vulnerability-list/vendor_id-12682/product_id-25085/Haxx-Libcurl.html&lt;/A&gt; &lt;/LI&gt;
  &lt;/UL&gt;
  &lt;UL&gt; 
   &lt;LI&gt;This can be found in the following location within the application: c:\program files (x86)\sap businessobjects\crystal reports for .net framework 4.0\common\sap businessobjects enterprise xi 4.0\win32_x86\libcurl.dll &lt;/LI&gt;
   &lt;LI&gt;3.Vulnerabilities exist because CRRuntime installs libssh2 version 1.4.3 which contain vulnerabilities according to the following Common Vulnerabilities datastore link:&lt;/LI&gt; 
  &lt;/UL&gt;
  &lt;A href="https://www.cvedetails.com/vulnerability-list/vendor_id-15300/product_id-31293/Libssh2-Libssh2.html"&gt;https://www.cvedetails.com/vulnerability-list/vendor_id-15300/product_id-31293/Libssh2-Libssh2.html&lt;/A&gt;
  &lt;BR /&gt;
  &lt;UL&gt;
   &lt;LI&gt;This can be found in the following location within the application:c:\program files (x86)\sap businessobjects\crystal reports for .net framework 4.0\common\sap businessobjects enterprise xi 4.0\win32_x86\libssh2.dll&lt;/LI&gt;
  &lt;/UL&gt;
  &lt;LI&gt;4.Vulnerabilities exist because CRRuntime installs openssl version 1.0.2h which contain vulnerabilities according to the following Common Vulnerabilities datastore link:&lt;/LI&gt; 
  &lt;A href="https://www.cvedetails.com/vulnerability-list/vendor_id-217/product_id-383/Openssl-Openssl.html"&gt;https://www.cvedetails.com/vulnerability-list/vendor_id-217/product_id-383/Openssl-Openssl.html&lt;/A&gt;
  &lt;BR /&gt; 
  &lt;UL&gt;
   &lt;LI&gt;This can be found in the following location within the application: c:\program files (x86)\sap businessobjects\crystal reports for .net framework 4.0\common\sap businessobjects enterprise xi 4.0\win32_x86\ssleaym32.dll&lt;/LI&gt;
  &lt;/UL&gt;
  &lt;LI&gt;5.Vulnerabilities exist because Arena Simulation version 16.x installs xercex version 3.1.4 which contain vulnerabilities according to the following Common Vulnerabilities datastore link:&lt;/LI&gt; 
  &lt;A href="https://www.cvedetails.com/vulnerability-list/vendor_id-45/product_id-31348/Apache-Xerces-c.html"&gt;https://www.cvedetails.com/vulnerability-list/vendor_id-45/product_id-31348/Apache-Xerces-c.html&lt;/A&gt;
  &lt;BR /&gt; 
  &lt;BR /&gt; 
  &lt;UL&gt;
   &lt;LI&gt;This can be found in the following location within the application: c:\program files (x86)\sap businessobjects\crystal reports for .net framework 4.0\common\sap businessobjects enterprise xi 4.0\win32_x86\xerces-c_3_1.dll&lt;/LI&gt;
  &lt;/UL&gt; 
  &lt;BR /&gt;</description>
      <pubDate>Mon, 16 Mar 2020 14:35:25 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/vulernabilities/m-p/12198809#M1981581</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2020-03-16T14:35:25Z</dc:date>
    </item>
  </channel>
</rss>

