Advisory
A note with CVSS 7.4 for component BC-MID-SCC was released by SAP on 13.02.2024. The correction/advisory 3424610 was described with "[CVE-2024-25642] Improper Certificate Validation in SAP Cloud Connector" and affects the system type SAP Cloud Connector.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process.
The vulnerability addressed is weak security function / cryptographic algorithm within SAP Cloud Connector.
Risk specification
Improper validation of certificates in SAP Cloud Connector allows an attacker to impersonate genuine servers, compromising mutual authentication and enabling interception of sensitive information.Solution
SAP Cloud Connectors certificate validation has been updated to include the required check to prevent impersonation and interception of sensitive information.