Advisory
On 09.06.2020 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within Adobe LiveCycle Designer.
SAP Note 2918762 addresses "Multiple vulnerabilities in Adobe LiveCycle Designer 11.0" to prevent xml injection vulnerability deserialization of untrusted data with a medium risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Risk specification
This version of the open source software contains XML Injection vulnerability that can result in an attacker tampering with XML documents through XML injection (dom4j). Also it enables attackers to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data (log4j).Solution
The vulnerable library has been exchanged with a fixed one.