Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2492 Missing XML Validation in SAP NetWeaver AS Java, SAP security note 2642680

SAP Note 2642680

SAP security note 2642680, "[CVE-2018-2492] Missing XML Validation in SAP NetWeaver AS Java", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

SAML 2.0 functionality in SAP NetWeaver AS Java does not sufficiently validate XML documents received from an untrusted source.

  • Retrieval of arbitrary files from the server
  • Denial-of-service conditions in successful exploits

Solution

Apply the corrective measures according to the Validity and SP Patch Level sections of this note.

CVSS

Score 7.1 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

References

Full note on SAP: SAP Support Launchpad note 2642680

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More