SAP security note 2457562, “[CVE-2017-16678] Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP NetWeaver Knowledge Management Configuration Service contains a vulnerability that allows an attacker to manipulate the application to send crafted requests on behalf of the application, resulting in a Server Side Request Forgery (SSRF) vulnerability.
Information gathering for further exploits or attacks.
Solution
- Remove the obsolete Configuration Exporter tool from the Knowledge Management Configuration Service.
- Implement the Support Packages and Patches referenced in this SAP Note.
CVSS
Score 6.6 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
References
Affected components
- EPBC2 7.00 to 7.02
- KMC-BC 7.30
- KMC-BC 7.31
- KMC-BC 7.40
- KMC-BC 7.50
- EPBC 7.00 to 7.02
Full note on SAP: SAP Support Launchpad note 2457562
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
