Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

XML External Entity vulnerability in SAP XML Parser, SAP security note 2111939

SAP Note 2111939

SAP security note 2111939, "XML External Entity vulnerability in SAP XML Parser". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can modify an XML-based request to include XML content that is parsed locally by the SAP XML Parser. This vulnerability could allow an attacker to:

  • Perform a denial of service (DoS) attack on the parsing system.
  • Disclose local data returned in the response to the malicious request.
  • Access further network-located resources accessible from the parsing system.

Solution

To address this vulnerability, check for the appropriate Support Package (SP) and Patch levels that fix the issue under the "Support Packages & Patches" tab within this note.

CVSS

Score 5.5 Vector: Network (N)/Low (L)/Single (S)/Partial (P)/None (N)/Partial (P)

References

Affected components

  • EP-PSERV: 7.00 to 7.02
  • EP-RUNTIME: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40

Full note on SAP: SAP Support Launchpad note 2111939

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More