Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure XML Encrypted SOAP messages, SAP security note 1687334

SAP Note 1687334

SAP security note 1687334, "Potential information disclosure XML Encrypted SOAP messages", addresses the following vulnerability. Below are the symptom, CVSS score, reason, SAP recommended solution, references and the affected software components.

Description

Symptom

An attacker can discover information related to XML Encrypted SOAP messages sent to NW ABAP. This information could be leveraged to tailor attacks specifically against XML Encrypted SOAP messages. Refer to the publication by Tibor Jager and Juraj Somorovsky, "How To Break XML Encryption", presented at the 18th ACM Conference on Computer and Communications Security (CCS), 2011.

Solution

  • For NW ABAP 7.20: The correction provided disables the use of XML Encryption in web services.
  • For Other Releases:
    • Check for Usage of XML Encryption: Use the report WSS_ENCRYPTION_CHECK attached to this note to verify if your system is utilizing XML Encryption.
    • Apply Corrections: If your system is affected, follow the correction instructions provided in this note.
    • Alternative Mitigation: Reconfigure the affected web services to use SSL for transport protection instead of XML Encryption.

Reason and prerequisites

Affected Systems: Web services configured to use XML Encryption in NW ABAP. Note that web services utilizing SSL are not impacted by this issue.

CVSS

Score 4.3 Vector: AV:N/AC:M/AU:N/C:P/I:N/A:N

References

Affected components

  • SAP_BASIS: 700 to 731

Full note on SAP: SAP Support Launchpad note 1687334

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More