Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update 1 to Security Note 2736825 – CVE-2019-0271 Denial of Service via XML External Entity (XXE) vulnerability in ABAP Server, SAP security note 2870067

SAP Note 2870067
Medium priority

SAP security note 2870067, "Update 1 to Security Note 2736825 – [CVE-2019-0271] Denial of Service via XML External Entity (XXE) vulnerability in ABAP Server", is a program error note released on 11.02.2020. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram error
PriorityCorrection with medium priority
StatusReleased for Customer
Released on11.02.2020

Description

Symptom

The ABAP Server (used in SAP NetWeaver, Suite/ERP, and S/4HANA) does not sufficiently validate XML documents accepted from untrusted sources. This vulnerability allows attackers to:

  • Retrieve arbitrary files from the server.
  • Trigger denial-of-service (DoS) conditions.

Solution

Upgrade to the following Kernel versions to mitigate the vulnerability:

  • Kernel 7.45, 7.49, or 7.53 (ABAP Server 7.40 to 7.52 or ABAP Platform)
  • Kernel 7.73 or 7.77 (ABAP Platform 7.53 or 7.54)

These versions include default settings for ixml/dtd_restriction and ixml/xml_expansion_factor to implement graceful behavior. SAP applications handle the new error situations by implementing interfaces as detailed in SAP Security Note 1594475 and SAP Note 1712860. It is recommended to review custom-developed applications accordingly.

Note: The correction for Kernel 7.53 is also included in Stack Kernel 753 PL501.

Reason and prerequisites

External entities may be used in Document Type Definitions (DTD). Such external entities can cause system resource exhaustion and are generally not required for SAP applications.

CVSS

Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

References

Affected components

  • KRNL64NUC: 7.49
  • KRNL64UC: 7.49, 7.53, 7.73
  • KERNEL: 7.49, 7.53, 7.73, 7.77, 7.78, 7.79

Full note on SAP: SAP Support Launchpad note 2870067

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More