SAP Security Note
Medium priority
SAP security note 2597875, "CVE-2018-2416: Missing XML Validation vulnerability in SAP Identity Management", is a program error note released on 18.05.2018. Below are the symptom, CVSS score, reason and prerequisites, SAP recommended solution and the affected software components.
Description
Symptom
Update 18th May 2018: This note has been re-released with updated "Reason and Prerequisites" information.
SAP Identity Management does not sufficiently validate an XML document accepted from an untrusted source.
Impacts:
- Arbitrary files retrieval from the server
- Denial-of-service conditions in successful exploits
Solution
For SAP Identity Management 8.0, this issue is fixed in 8.0 SP06.
Reason and prerequisites
You are using SAP Identity Management 8.0 SP00-SP05.
CVSS
Score 4.3 / 10 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Affected components
- IDMREST: From 8.0 to 8.0
Full note on SAP: SAP Support Launchpad note 2597875
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




