SAP security note 2689259, "[CVE-2019-0268] Missing XML Validation vulnerability in SAP BusinessObjects BI Platform CMC module". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The SAP BusinessObjects BI Platform Central Management Console (CMC) module has a Missing XML Validation vulnerability. The XML parser does not sufficiently validate XML documents from untrusted sources, potentially allowing malicious actors to exploit this weakness.
- Arbitrary File Retrieval: Attackers may retrieve arbitrary files from the server.
- Denial of Service (DoS): Successful exploitation can lead to DoS conditions.
Solution
The issue has been addressed by securely configuring the XML parser to disallow external entities in incoming XML documents. To remediate this vulnerability, apply the relevant security patches listed below.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
References
- SAP Note 2689259
- CVE-2019-0268
Affected components
- SAP BusinessObjects Business Intelligence Platform (BI) 4.1
- SAP BusinessObjects Business Intelligence Platform (BI) 4.2
- SAP BusinessObjects Business Intelligence Platform (BI) 4.3
Full note on SAP: SAP Support Launchpad note 2689259
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
