Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing XML Validation vulnerability in Enterprise Portal, SAP security note 2369541

SAP Note 2369541SAP Security NoteMedium priority

SAP security note 2369541, "Missing XML Validation vulnerability in Enterprise Portal", is a program error note released on 14.02.2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentEnterprise Portal > SAP Enterprise Portal (On-Premise) > iViews > Upload content and actions
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on14.02.2017
LanguageEnglish

Description

Symptom

Enterprise Portal does not sufficiently validate an XML document accepted from an untrusted source.

Some well-known impacts of Missing XML Validation vulnerability are:

  • Arbitrary files retrieval from the server
  • Denial-of-service conditions in successful exploits

Solution

Added validation to the accepted XML document. Under the "Support Packages & Patches" tab within this note, you can check for the appropriate SP & Patch level fixing this issue.

Reason and prerequisites

Prerequisites: XML document is accepted from an untrusted source.

Reason: XML validation is missing.

CVSS

Score 6.5

References

Affected components

  • EP-ADMIN 7.10 to 7.11
  • EP-ADMIN 7.20
  • EP-ADMIN 7.30

Full note on SAP: SAP Support Launchpad note 2369541

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More