Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing XML Validation vulnerability in Knowledge Management ICE Service, SAP security note 2387249

SAP Note 2387249
Medium priority

SAP security note 2387249, "Missing XML Validation vulnerability in Knowledge Management ICE Service", was released on April 11, 2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentEnterprise Portal > Enterprise Portal – Knowledge Management and Collaboration > Content Management > Content Exchange (EP-KM-CM-ICE)
PriorityCorrection with medium priority
StatusReleased for Customer
Released onApril 11, 2017

Description

Symptom

Knowledge Management ICE Service does not sufficiently validate an XML document accepted from an untrusted source. This Missing XML Validation vulnerability can lead to:

  • Arbitrary file retrieval from the server
  • Denial-of-Service (DoS) conditions in successful exploits

Solution

  • Configure Knowledge Management ICE Service to properly validate all XML inputs.
  • Implement the necessary support packages and patches as mentioned in this note to address the vulnerability.

CVSS

Score 4.9 Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

References

Affected components

  • KMC-CM 7.00 to 7.02
  • KMC-CM 7.30 to 7.50
  • KMC-CM 7.31 to 7.40
  • KMC-CM 7.50

Full note on SAP: SAP Support Launchpad note 2387249

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More