SAP Security Note
Medium priority
SAP security note 2915126, "[CVE-2020-6260] Incomplete XML Validation in SAP Solution Manager (Trace Analysis)", is a program error note released on 09.06.2020. Below are the symptom and SAP recommended solution.
Description
Symptom
This note addresses two vulnerabilities caused by incomplete XML validation:
- CVE-2020-6260: SAP Solution Manager (Trace Analysis) allows an attacker to inject superfluous data that can be displayed by the application. The application shows additional data that do not actually exist. CVSS 6.5, Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L.
- CVE-2020-6261: Allows log injection into the trace file, impairing the readability of the trace file. CVSS 5.3, Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N.
Solution
The application will no longer allow unauthorized data to be written into the trace file. Apply the latest LM-SERVICE patch as detailed below.
Reason and prerequisites
Incomplete XML validation in SAP Solution Manager leads to the mentioned vulnerabilities.
CVSS
Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
References
- CVE-2020-6260
- CVE-2020-6261
Full note on SAP: SAP Support Launchpad note 2915126
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
