Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing XML Validation vulnerability in SAP Note Assistant, SAP security note 2425129

SAP Note 2425129

SAP security note 2425129, "Missing XML Validation vulnerability in SAP Note Assistant", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

UPDATE 28th January 2019: This note has been re-released with updated "Reason and Prerequisites" information. Additionally, CVSS information is also made available.

SAP Note Assistant does not sufficiently validate an XML document accepted from an untrusted source.

Some well-known impacts of Missing XML Validation vulnerability are:

  • Arbitrary files retrieval from the server
  • Denial-of-service conditions in successful exploits

Solution

Additional checks are added in code to restrict external entity references.

Please implement the relevant correction instructions or update to the corresponding support package to protect against this vulnerability.

Reason and prerequisites

If SAP Note 2019086 is valid for your system and you want to implement it, kindly do so before implementing this SAP Note 2425129.

CVSS

Score 6.9 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:L

References

Affected components

  • SAP_BASIS 700 to 702
  • SAP_BASIS 710 to 711
  • SAP_BASIS 730
  • SAP_BASIS 731
  • SAP_BASIS 740
  • SAP_BASIS 750 to 751

Full note on SAP: SAP Support Launchpad note 2425129

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More