Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2017-16678 Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, SAP security note 2457562

SAP Note 2457562

SAP security note 2457562, “[CVE-2017-16678] Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP NetWeaver Knowledge Management Configuration Service contains a vulnerability that allows an attacker to manipulate the application to send crafted requests on behalf of the application, resulting in a Server Side Request Forgery (SSRF) vulnerability.

Information gathering for further exploits or attacks.

Solution

  • Remove the obsolete Configuration Exporter tool from the Knowledge Management Configuration Service.
  • Implement the Support Packages and Patches referenced in this SAP Note.

CVSS

Score 6.6 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

References

Affected components

  • EPBC2 7.00 to 7.02
  • KMC-BC 7.30
  • KMC-BC 7.31
  • KMC-BC 7.40
  • KMC-BC 7.50
  • EPBC 7.00 to 7.02

Full note on SAP: SAP Support Launchpad note 2457562

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More