SAP security note 2642680, "[CVE-2018-2492] Missing XML Validation in SAP NetWeaver AS Java", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
SAML 2.0 functionality in SAP NetWeaver AS Java does not sufficiently validate XML documents received from an untrusted source.
- Retrieval of arbitrary files from the server
- Denial-of-service conditions in successful exploits
Solution
Apply the corrective measures according to the Validity and SP Patch Level sections of this note.
CVSS
Score 7.1 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
References
Full note on SAP: SAP Support Launchpad note 2642680
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
