High
SAP security note 2931391, “[CVE-2020-6271] Missing XML Validation in SAP Solution Manager (Problem Context Manager)”, is a note released on June 9, 2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The Problem Context Manager application in SAP Solution Manager lacks necessary XML validation. This vulnerability allows an attacker to consume large amounts of memory, potentially causing the system to crash, and to achieve a minor loss of confidentiality.
Solution
The vulnerable feature is deprecated. To mitigate this issue, apply the latest LM-SERVICE patch, which deactivates the affected servlet. For detailed instructions, refer to SAP Note 2930617.
CVSS
Score 8.2 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
References
- CVE-2020-6271
Affected components
- SAP Solution Manager 7.20
Full note on SAP: SAP Support Launchpad note 2931391
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
