Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6260 Incomplete XML Validation in SAP Solution Manager (Trace Analysis), SAP security note 2915126

SAP Note 2915126
SAP Security Note
Medium priority

SAP security note 2915126, "[CVE-2020-6260] Incomplete XML Validation in SAP Solution Manager (Trace Analysis)", is a program error note released on 09.06.2020. Below are the symptom and SAP recommended solution.

ComponentService > SAP Solution Manager > Diagnostics > Applications > Trace Analysis
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version12
StatusReleased for Customer
Released on09.06.2020
LanguageEnglish

Description

Symptom

This note addresses two vulnerabilities caused by incomplete XML validation:

  • CVE-2020-6260: SAP Solution Manager (Trace Analysis) allows an attacker to inject superfluous data that can be displayed by the application. The application shows additional data that do not actually exist. CVSS 6.5, Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L.
  • CVE-2020-6261: Allows log injection into the trace file, impairing the readability of the trace file. CVSS 5.3, Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N.

Solution

The application will no longer allow unauthorized data to be written into the trace file. Apply the latest LM-SERVICE patch as detailed below.

Reason and prerequisites

Incomplete XML validation in SAP Solution Manager leads to the mentioned vulnerabilities.

CVSS

Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

References

  • CVE-2020-6260
  • CVE-2020-6261

Full note on SAP: SAP Support Launchpad note 2915126

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More