Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

MDX SOAP / XMLA interface and Document Type Definitions, SAP security note 1597066

SAP Note 1597066

SAP security note 1597066, "MDX: SOAP/XMLA Interface and Document Type Definitions". Below are the symptom, SAP recommended solution and the affected software components.

ComponentSAP Business Warehouse > Business Explorer > OLAP Technology > MDX, OLAP-BAPI, OLE DB for OLAP

Description

Symptom

An attacker can attempt to generate a "denial of service" situation or start an "SMB relay attack" using Document Type Definitions (DTD) via the SOAP/XMLA interface.

Solution

This correction prevents the use of Document Type Definitions when you use the SOAP/XMLA interface.

WarningYou must perform this manual pre-implementation step manually and separately in each system before you import the Note to implement. For BW Releases BW 3.0B, BW 3.1 Content, and BW 3.50, you must apply the patch level specified in SAP Note 1594475. Only then can you prevent the use of Document Type Definitions.

Reason and prerequisites

There is a program error. Document Type Definitions must not occur in SOAP requests.

CVSS

Score 4.0 Vector: AV:N/AC:L/AU:S/C:N/I:N/A:P

References

Affected components

  • SAP Business Warehouse > Business Explorer > OLAP Technology > MDX, OLAP-BAPI, OLE DB for OLAP

Full note on SAP: SAP Support Launchpad note 1597066

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More