SAP security note 2369541, "Missing XML Validation vulnerability in Enterprise Portal", is a program error note released on 14.02.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Enterprise Portal does not sufficiently validate an XML document accepted from an untrusted source.
Some well-known impacts of Missing XML Validation vulnerability are:
- Arbitrary files retrieval from the server
- Denial-of-service conditions in successful exploits
Solution
Added validation to the accepted XML document. Under the "Support Packages & Patches" tab within this note, you can check for the appropriate SP & Patch level fixing this issue.
Reason and prerequisites
Prerequisites: XML document is accepted from an untrusted source.
Reason: XML validation is missing.
CVSS
Score 6.5
References
Affected components
- EP-ADMIN 7.10 to 7.11
- EP-ADMIN 7.20
- EP-ADMIN 7.30
Full note on SAP: SAP Support Launchpad note 2369541
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
