Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6187Missing XML Validation vulnerability in SAP NetWeaver(Guided Procedures), SAP security note 2864415

SAP Note 2864415
SAP Security Note
Medium priority

SAP security note 2864415, "[CVE-2020-6187] Missing XML Validation vulnerability in SAP NetWeaver(Guided Procedures)", is a program error note released on 11.02.2020. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Guided Procedures (BC-GP)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version7
StatusReleased for Customer
Released on11.02.2020
LanguageEnglish

Description

Symptom

Guided Procedures does not sufficiently validate an XML document accepted from an untrusted source.

Some well-known impacts of Missing XML Validation vulnerability are:

  • Denial-of-service conditions in successful exploits

Solution

The XML parser is now configured securely so that it does not allow external entities as part of an incoming XML document.

To correct this problem, implement the Support Packages and Patches referenced by this SAP Note.

CVSS

Score 4.9 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Full note on SAP: SAP Support Launchpad note 2864415

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More