Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing XML Validation in Composite Application Framework Authorization Tool, SAP security note 2372301

SAP Note 2372301
SAP Security Note
Medium priority

SAP security note 2372301, "Missing XML Validation in Composite Application Framework Authorization Tool", is a note released on 02.11.2017. Below are the symptom and SAP recommended solution.

ComponentBasis Components > ABAP Workbench, Java IDE and Infrastructure > CE Developer Studio – Please read SAP note 1179668 > Composite Application Framework
PriorityMedium priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released on02.11.2017

Description

Symptom

UPDATE 2nd November: This note has been re-released with updated “Support Packages & Patches” information.

Composite Application Framework Authorization Tool launched from NetWeaver Administrator does not sufficiently validate an XML document when imported.

Some well-known impacts of Missing XML Validation vulnerability are:

  • Arbitrary files retrieval from the server
  • Denial-of-service conditions in successful exploits

Solution

The XML parser is now configured securely so that it does not allow external entities as part of an incoming XML document. Implement the Support Packages and Patches referenced by this SAP Note.

Full note on SAP: SAP Support Launchpad note 2372301

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More