Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0277 XML External Entity vulnerability in SAP HANA extended application services, advanced, SAP security note 2764283

SAP Note 2764283SAP Security NoteHigh priority

SAP security note 2764283, "[CVE-2019-0277] XML External Entity vulnerability in SAP HANA extended application services, advanced", is a program error note released on 12.03.2019. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > HANA XS Advanced > XS Advanced Runtime / XS Controller
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on12.03.2019
LanguageEnglish

Description

Symptom

SAP HANA extended application services, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space.

Some well-known impacts of XML External Entity vulnerability are:

  • Arbitrary files retrieval from the server
  • Resource consumption in successful exploits

Solution

The issue has been fixed with XS advanced runtime version 1.0.102. Update to this or later versions.

Reason and prerequisites

Prerequisite is that the attacker has either administrative or developer privileges to the SAP space of the XS advanced service.

CVSS

Score 8.7 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H

Affected components

  • SAP_EXTENDED_APP_SERVICES (from version 1 to 1)

Full note on SAP: SAP Support Launchpad note 2764283

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More