Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2416 Missing XML Validation vulnerability in SAP Identity Management, SAP security note 2597875

SAP Note 2597875
SAP Security Note
Medium priority

SAP security note 2597875, "CVE-2018-2416: Missing XML Validation vulnerability in SAP Identity Management", is a program error note released on 18.05.2018. Below are the symptom, CVSS score, reason and prerequisites, SAP recommended solution and the affected software components.

ComponentBasis Components > Identity and Access Management > Identity Management
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on18.05.2018
LanguageEnglish

Description

Symptom

Update 18th May 2018: This note has been re-released with updated "Reason and Prerequisites" information.

SAP Identity Management does not sufficiently validate an XML document accepted from an untrusted source.

Impacts:

  • Arbitrary files retrieval from the server
  • Denial-of-service conditions in successful exploits

Solution

For SAP Identity Management 8.0, this issue is fixed in 8.0 SP06.

Reason and prerequisites

You are using SAP Identity Management 8.0 SP00-SP05.

CVSS

Score 4.3 / 10 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Affected components

  • IDMREST: From 8.0 to 8.0

Full note on SAP: SAP Support Launchpad note 2597875

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More

Three identical server cabinets carrying stacks of code of very different heights beside a measuring rule

ABAP Code Security Scan Cost Drivers

What moves the cost of an ABAP code security scan: custom object counts, effective lines, systems in scope, transport gating, triage and retest.