Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Untrusted XML input parsing possible in CA-WUI-UI-TAG, SAP security note 1909665

SAP Note 1909665

SAP security note 1909665, "Untrusted XML input parsing possible in CA-WUI-UI-TAG". Below are the symptom, SAP recommended solution and the affected software components.

ComponentCross-Application Components > WebClient User Interface > User Interface > Tag Library (CA-WUI-UI-TAG)

Description

Symptom

A malicious user can modify an XML-based request to include XML content that is then parsed locally. This could allow a malicious user to perform a denial of service (DoS) on the parsing system, disclose local data that is returned in the response to the malicious request, or access further network-located resources accessible from the parsing system.

Solution

Install the attached correction instructions or the corresponding Support Package relevant to your software component version.

CVSS

Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N

References

Affected components

  • CRMUIF 600
  • WEBCUIF 700, 701, 730, 731, 746, 747
  • SAP_BASIS 640 to 730

Full note on SAP: SAP Support Launchpad note 1909665

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More