Medium priority
SAP security note 2387249, "Missing XML Validation vulnerability in Knowledge Management ICE Service", was released on April 11, 2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Knowledge Management ICE Service does not sufficiently validate an XML document accepted from an untrusted source. This Missing XML Validation vulnerability can lead to:
- Arbitrary file retrieval from the server
- Denial-of-Service (DoS) conditions in successful exploits
Solution
- Configure Knowledge Management ICE Service to properly validate all XML inputs.
- Implement the necessary support packages and patches as mentioned in this note to address the vulnerability.
CVSS
Score 4.9 Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
References
Affected components
- KMC-CM 7.00 to 7.02
- KMC-CM 7.30 to 7.50
- KMC-CM 7.31 to 7.40
- KMC-CM 7.50
Full note on SAP: SAP Support Launchpad note 2387249
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




