SAP security note 2425129, "Missing XML Validation vulnerability in SAP Note Assistant", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
UPDATE 28th January 2019: This note has been re-released with updated "Reason and Prerequisites" information. Additionally, CVSS information is also made available.
SAP Note Assistant does not sufficiently validate an XML document accepted from an untrusted source.
Some well-known impacts of Missing XML Validation vulnerability are:
- Arbitrary files retrieval from the server
- Denial-of-service conditions in successful exploits
Solution
Additional checks are added in code to restrict external entity references.
Please implement the relevant correction instructions or update to the corresponding support package to protect against this vulnerability.
Reason and prerequisites
If SAP Note 2019086 is valid for your system and you want to implement it, kindly do so before implementing this SAP Note 2425129.
CVSS
Score 6.9 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:L
References
Affected components
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 711
- SAP_BASIS 730
- SAP_BASIS 731
- SAP_BASIS 740
- SAP_BASIS 750 to 751
Full note on SAP: SAP Support Launchpad note 2425129
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
