SAP security note 1687334, "Potential information disclosure XML Encrypted SOAP messages", addresses the following vulnerability. Below are the symptom, CVSS score, reason, SAP recommended solution, references and the affected software components.
Description
Symptom
An attacker can discover information related to XML Encrypted SOAP messages sent to NW ABAP. This information could be leveraged to tailor attacks specifically against XML Encrypted SOAP messages. Refer to the publication by Tibor Jager and Juraj Somorovsky, "How To Break XML Encryption", presented at the 18th ACM Conference on Computer and Communications Security (CCS), 2011.
Solution
- For NW ABAP 7.20: The correction provided disables the use of XML Encryption in web services.
- For Other Releases:
- Check for Usage of XML Encryption: Use the report WSS_ENCRYPTION_CHECK attached to this note to verify if your system is utilizing XML Encryption.
- Apply Corrections: If your system is affected, follow the correction instructions provided in this note.
- Alternative Mitigation: Reconfigure the affected web services to use SSL for transport protection instead of XML Encryption.
Reason and prerequisites
Affected Systems: Web services configured to use XML Encryption in NW ABAP. Note that web services utilizing SSL are not impacted by this issue.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:P/I:N/A:N
References
Referenced by
Affected components
- SAP_BASIS: 700 to 731
Full note on SAP: SAP Support Launchpad note 1687334
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
