SAP Security Note
High priority
SAP security note 1890819, "Untrusted XML input parsing possible in Hotspot Analysis", is a program error note released on 24.07.2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can modify an XML-based response to include XML content that is then parsed locally. This could allow a malicious user to perform a denial of service (DoS) on the parsing system, or access further network-located resources accessible from the parsing system.
Solution
Implement the support package or the correction instruction. If implementing the correction instruction, note 1594475 must be implemented beforehand; the system must be at least at the support package level described in note 1594475.
Reason and prerequisites
The problem is caused by a program error due to the incorrect use of an XML parser.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:S/C:N/I:N/A:P
References
This note refers to
Affected components
- SAP_BASIS 701 to 702
- SAP_BASIS 711 to 730
- SAP_BASIS 731
- SAP_BASIS 740
Full note on SAP: SAP Support Launchpad note 1890819
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




