SAP security note 2969457, "CVE-2020-6366: Missing XML Validation in SAP NetWeaver (Compare Systems)". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP NetWeaver (Compare Systems) does not sufficiently validate uploaded XML documents. An attacker with administrative privileges can retrieve arbitrary files, including files on the OS level from the server, and/or execute a denial-of-service.
Solution
The XML parser is now configured securely to prevent external entities from being part of incoming XML documents.
- Implement the Support Packages and Patches referenced in this SAP Security Note.
- There are no known impacts on existing functionalities after applying the security note.
CVSS
Score 7.6 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
References
Affected components
- Basis Components > NetWeaver Application Server Java > Local Admin Tools > Monitoring (BC-JAS-ADM-MON) – versions 7.20, 7.30, 7.31, 7.40, 7.50
Full note on SAP: SAP Support Launchpad note 2969457
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
