SAP security note 2372626, "Missing XML Validation Vulnerability in SAP NetWeaver Log Viewer". Below are the symptom and SAP recommended solution.
Description
Symptom
The Log Viewer application in SAP NetWeaver Administrator does not sufficiently validate an XML document accepted from an untrusted source. This Missing XML Validation vulnerability can lead to:
- Arbitrary file retrieval from the server
- Denial-of-Service (DoS) conditions in successful exploits
Solution
The XML parser is now configured securely to disallow external entities in incoming XML documents. To address this vulnerability:
- Apply the Support Packages and Patches referenced in this SAP Note.
- Enable the XML Hardener as described in the manual activities for this note.
CVSS
Score 5.5/10 Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L
References
- SAP Note 2248846: XML Hardener Service Start Error
- SAP Note 2332237: SAP NetWeaver 7.30 SP17 – NWDS Update Site Standalone
- SAP Note 2463530: Central Note for SAP NetWeaver 7.31 SP20 Application Server Java
Full note on SAP: SAP Support Launchpad note 2372626
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




