Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0268 Missing XML Validation vulnerability in SAP BusinessObjects BI Platform CMC module, SAP security note 2689259

SAP Note 2689259

SAP security note 2689259, "[CVE-2019-0268] Missing XML Validation vulnerability in SAP BusinessObjects BI Platform CMC module". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The SAP BusinessObjects BI Platform Central Management Console (CMC) module has a Missing XML Validation vulnerability. The XML parser does not sufficiently validate XML documents from untrusted sources, potentially allowing malicious actors to exploit this weakness.

  • Arbitrary File Retrieval: Attackers may retrieve arbitrary files from the server.
  • Denial of Service (DoS): Successful exploitation can lead to DoS conditions.

Solution

The issue has been addressed by securely configuring the XML parser to disallow external entities in incoming XML documents. To remediate this vulnerability, apply the relevant security patches listed below.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

References

Affected components

  • SAP BusinessObjects Business Intelligence Platform (BI) 4.1
  • SAP BusinessObjects Business Intelligence Platform (BI) 4.2
  • SAP BusinessObjects Business Intelligence Platform (BI) 4.3

Full note on SAP: SAP Support Launchpad note 2689259

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More