SAP security note 2764283, "[CVE-2019-0277] XML External Entity vulnerability in SAP HANA extended application services, advanced", is a program error note released on 12.03.2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP HANA extended application services, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space.
Some well-known impacts of XML External Entity vulnerability are:
- Arbitrary files retrieval from the server
- Resource consumption in successful exploits
Solution
The issue has been fixed with XS advanced runtime version 1.0.102. Update to this or later versions.
Reason and prerequisites
Prerequisite is that the attacker has either administrative or developer privileges to the SAP space of the XS advanced service.
CVSS
Score 8.7 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H
Affected components
- SAP_EXTENDED_APP_SERVICES (from version 1 to 1)
Full note on SAP: SAP Support Launchpad note 2764283
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
