on 2024 Dec 20 6:00 AM
Hi All,
We have an application that uses the Crystal Reports Runtime (CRR). Recently, through an internal vulnerability scan we found that the latest version of CRR i.e. v.13_0_37 is still using a vulnerable version of libcurl.dll(v.8.4.0.0) which has been flagged in the NIST Database NVD - cve-2024-7264.
Wanted to know if the dev team at SAP has any upgrade timeline to update this vulnerable version of libcurl.dll to v.8.9.1 or higher?
Request clarification before answering.
Hello,
From the SAP Developers:
This CVE NVD - cve-2024-7264. had already been assessed internally since the function GTime2str() mentioned was never used by our code.
So it did not impact CR Runtime. If there’s any critical CVE and the risk could not be mitigated, then we will upgrade the corresponding tp(third party) component.
So as I mentioned it doesn't affect CR runtime so just flag it as not critical in your scans.
Merry Christmas and Happy New Year
Don
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I have not found anything about it so I pinged SAP Developers to see what they have to say...
They are in Shanghai so it'll be a day or so for a response.
Typically if the API reported is not used in CR they won't fix anything so you can simply ignore the reported scan.
Upgrading r3rd party references is a huge amount of work so they won't upgrade it if the reported issue is not used in CR's runtime.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 7 | |
| 7 | |
| 6 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.