<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: Security Vulnerability in SAP Crystal Reports for Ecl... in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/security-vulnerability-in-sap-crystal-reports-for-eclipse-java-sp31-cve/qaa-p/14037579#M4906131</link>
    <description>&lt;P&gt;I pinged R&amp;amp;D to comment on this one.&lt;/P&gt;&lt;P&gt;Often though there are reported CVE's but CR doesn't use that part so it doesn't affect the use in CR Applications.&lt;/P&gt;&lt;P&gt;If you have concerns for your implementation in your app you will need to show R&amp;amp;D how your app is vulnerable in a test app they can look at.&lt;/P&gt;&lt;P&gt;They are in Shanghai so it may take a few days to get a response...&lt;/P&gt;</description>
    <pubDate>Sat, 08 Mar 2025 11:33:48 GMT</pubDate>
    <dc:creator>DonWilliams</dc:creator>
    <dc:date>2025-03-08T11:33:48Z</dc:date>
    <item>
      <title>Security Vulnerability in SAP Crystal Reports for Eclipse (JAVA) SP31 - CVE-2024-21742</title>
      <link>https://community.sap.com/t5/technology-q-a/security-vulnerability-in-sap-crystal-reports-for-eclipse-java-sp31-cve/qaq-p/14037138</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Regarding Crystal report for eclipse (java) - SP31;&lt;/P&gt;&lt;P&gt;Looks like there is vulnerability &lt;STRONG&gt;CVE-2024-21742&lt;/STRONG&gt; in file:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;lib/xmlconnector.jar/lib/apache-mime4j-core-0.8.9.jar&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;version 0.8.10 and beyond does not have this vulnerability:&lt;BR /&gt;&lt;A href="https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-core" target="_blank"&gt;https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-core&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;CVE details:&lt;BR /&gt;Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages.&lt;/P&gt;&lt;P&gt;Can someone confirm if this is effected by this CVE, and if so can this be a hotfix or new service pack?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 16:40:42 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/security-vulnerability-in-sap-crystal-reports-for-eclipse-java-sp31-cve/qaq-p/14037138</guid>
      <dc:creator>neilpayne-1</dc:creator>
      <dc:date>2025-03-07T16:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Security Vulnerability in SAP Crystal Reports for Ecl...</title>
      <link>https://community.sap.com/t5/technology-q-a/security-vulnerability-in-sap-crystal-reports-for-eclipse-java-sp31-cve/qaa-p/14037579#M4906131</link>
      <description>&lt;P&gt;I pinged R&amp;amp;D to comment on this one.&lt;/P&gt;&lt;P&gt;Often though there are reported CVE's but CR doesn't use that part so it doesn't affect the use in CR Applications.&lt;/P&gt;&lt;P&gt;If you have concerns for your implementation in your app you will need to show R&amp;amp;D how your app is vulnerable in a test app they can look at.&lt;/P&gt;&lt;P&gt;They are in Shanghai so it may take a few days to get a response...&lt;/P&gt;</description>
      <pubDate>Sat, 08 Mar 2025 11:33:48 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/security-vulnerability-in-sap-crystal-reports-for-eclipse-java-sp31-cve/qaa-p/14037579#M4906131</guid>
      <dc:creator>DonWilliams</dc:creator>
      <dc:date>2025-03-08T11:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Security Vulnerability in SAP Crystal Reports for Ecl...</title>
      <link>https://community.sap.com/t5/technology-q-a/security-vulnerability-in-sap-crystal-reports-for-eclipse-java-sp31-cve/qaa-p/14040852#M4906486</link>
      <description>&lt;P&gt;Thank you DonWilliams.&lt;/P&gt;&lt;P&gt;For context, xmlconnector is a file which is distributed for the crystal reports runtime for eclipse, currently we distribute all files from the lib folder with our java wrapper application. Are we saying depending on the java wrapper that jar may not be used? If so is there any information of what it is used for by crystal report engine?&lt;BR /&gt;&lt;BR /&gt;Also, any update from R&amp;amp;D as yet?&lt;/P&gt;&lt;P&gt;Thank you very much!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 15:36:48 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/security-vulnerability-in-sap-crystal-reports-for-eclipse-java-sp31-cve/qaa-p/14040852#M4906486</guid>
      <dc:creator>neilpayne-1</dc:creator>
      <dc:date>2025-03-11T15:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Security Vulnerability in SAP Crystal Reports for Ecl...</title>
      <link>https://community.sap.com/t5/technology-q-a/security-vulnerability-in-sap-crystal-reports-for-eclipse-java-sp31-cve/qaa-p/14043448#M4906756</link>
      <description>&lt;P&gt;I heard back from R&amp;amp;D:&lt;/P&gt;&lt;P&gt;&lt;U&gt;apache-mime4j-core-0.8.9.jar is used to parse XML/web service data sources, If you don’t use XML/web service as the data source, this CVE won’t affect you.&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;When using Crystal Report for Eclipse, users must first ensure that the data source is secure, so the impact of this CVE on us is also limited.&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Additionally, we can consider upgrading it in SP32.&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Hope this answers your questions?&lt;/P&gt;&lt;P&gt;Don&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 17:55:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/security-vulnerability-in-sap-crystal-reports-for-eclipse-java-sp31-cve/qaa-p/14043448#M4906756</guid>
      <dc:creator>DonWilliams</dc:creator>
      <dc:date>2025-03-13T17:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Security Vulnerability in SAP Crystal Reports for Ecl...</title>
      <link>https://community.sap.com/t5/technology-q-a/security-vulnerability-in-sap-crystal-reports-for-eclipse-java-sp31-cve/qaa-p/14043635#M4906770</link>
      <description>&lt;P&gt;Thank you again DonWilliams&lt;/P&gt;&lt;P&gt;That is good to know, we do not use XML/Web services as the datasource, so we are testing the application without this jar file and so far it seems OK&lt;/P&gt;&lt;P&gt;Regarding SP32, that doesnt seem to be available on the website?&lt;BR /&gt;&lt;A href="https://pages.community.sap.com/topics/crystal-reports" target="_blank" rel="noopener"&gt;https://pages.community.sap.com/topics/crystal-reports&lt;/A&gt;&lt;BR /&gt;note that SP31 is the latest service pack for SAP Crystal Reports for Eclipse (JAVA) on that link&lt;BR /&gt;Is there another public link for SP32?&lt;BR /&gt;&lt;BR /&gt;EDIT: i just realised you said you COULD upgrade it in SP32, please do!&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 11:11:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/security-vulnerability-in-sap-crystal-reports-for-eclipse-java-sp31-cve/qaa-p/14043635#M4906770</guid>
      <dc:creator>neilpayne-1</dc:creator>
      <dc:date>2025-03-14T11:11:57Z</dc:date>
    </item>
  </channel>
</rss>

