Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6366 Missing XML Validation in SAP NetWeaver (Compare Systems), SAP security note 2969457

SAP Note 2969457

SAP security note 2969457, "CVE-2020-6366: Missing XML Validation in SAP NetWeaver (Compare Systems)". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP NetWeaver (Compare Systems) does not sufficiently validate uploaded XML documents. An attacker with administrative privileges can retrieve arbitrary files, including files on the OS level from the server, and/or execute a denial-of-service.

Solution

The XML parser is now configured securely to prevent external entities from being part of incoming XML documents.

  • Implement the Support Packages and Patches referenced in this SAP Security Note.
  • There are no known impacts on existing functionalities after applying the security note.

CVSS

Score 7.6 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

References

Affected components

  • Basis Components > NetWeaver Application Server Java > Local Admin Tools > Monitoring (BC-JAS-ADM-MON) – versions 7.20, 7.30, 7.31, 7.40, 7.50

Full note on SAP: SAP Support Launchpad note 2969457

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More