SAP Security Note
Medium priority
SAP security note 2864415, "[CVE-2020-6187] Missing XML Validation vulnerability in SAP NetWeaver(Guided Procedures)", is a program error note released on 11.02.2020. Below are the symptom and SAP recommended solution.
Description
Symptom
Guided Procedures does not sufficiently validate an XML document accepted from an untrusted source.
Some well-known impacts of Missing XML Validation vulnerability are:
- Denial-of-service conditions in successful exploits
Solution
The XML parser is now configured securely so that it does not allow external entities as part of an incoming XML document.
To correct this problem, implement the Support Packages and Patches referenced by this SAP Note.
CVSS
Score 4.9 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Full note on SAP: SAP Support Launchpad note 2864415
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
