SAP security note 1908531, “Untrusted XML input parsing possible in SBOP Explorer”, is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can modify an XML-based request to include XML content that is then parsed locally. This vulnerability could allow a denial of service (DoS) on the parsing system, disclose local data in the response to the malicious request, or access further network-located resources accessible from the parsing system.
Solution
The issue is resolved in the following SAP BI versions:
- BI 4.0 SP9 Patch 2 and later
- BI 4.0 SP10
- BI 4.1 SP3 Patch 2 and later
- BI 4.1 SP4
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
Affected components
- Business Intelligence Solutions > Reporting, Analysis, and Dashboards > Obsolete: Polestar, Explorer (BI-RA-EXP)
Full note on SAP: SAP Support Launchpad note 1908531
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
