Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0396 Missing XML Validation vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), SAP security note 2814007

SAP Note 2814007
SAP Security Note
High priority

SAP security note 2814007, "[CVE-2019-0396] Missing XML Validation vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)", is a program error note released on 11.11.2019. Below are the symptom and SAP recommended solution.

ComponentBusiness intelligence solutions > Reporting, analysis, and dashboards > Web Intelligence > Front End/Client > HTML Front End
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version8
StatusReleased for Customer
Released on11.11.2019
LanguageEnglish

Description

Symptom

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) does not sufficiently validate an XML document accepted from an untrusted source.
An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.

Some well-known impacts of Missing XML Validation vulnerability are:

  • Arbitrary file retrieval from the server
  • Denial-of-service conditions in successful exploits

Solution

An XML input validator has been introduced for the affected workflows. This issue is fixed in the patches listed in the Support Packages & Patches section below.

For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559 in the References section.

Reason and prerequisites

Cause: An XML input was not validated correctly.

CVSS

Score 7.1 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

References

Full note on SAP: SAP Support Launchpad note 2814007

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More