Description
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) does not sufficiently validate an XML document accepted from an untrusted source.
An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific worklfows.
Some well-known impacts of Missing XML Validation vulnerability are –
- arbitrary files retrieval from the server
- denial-of-service conditions in successful exploits
Available fix and Supported packages
- ENTERPRISE | 410 | 410
- ENTERPRISE | 420 | 420
- SBOP BI PLATFORM SERVERS 4.1 | SP012 | 000200
- SBOP BI PLATFORM SERVERS 4.2 | SP006 | 001000
- SBOP BI PLATFORM SERVERS 4.2 | SP007 | 000500
- SBOP BI PLATFORM SERVERS 4.2 | SP008 | 000000
Affected component
- BI-RA-WBI-FE-HTM
HTML Front End
CVSS
Score: 7.1
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/2814007