SAP Security Note
High priority
SAP security note 2814007, "[CVE-2019-0396] Missing XML Validation vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)", is a program error note released on 11.11.2019. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) does not sufficiently validate an XML document accepted from an untrusted source.
An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.
Some well-known impacts of Missing XML Validation vulnerability are:
- Arbitrary file retrieval from the server
- Denial-of-service conditions in successful exploits
Solution
An XML input validator has been introduced for the affected workflows. This issue is fixed in the patches listed in the Support Packages & Patches section below.
For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559 in the References section.
Reason and prerequisites
Cause: An XML input was not validated correctly.
CVSS
Score 7.1 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
References
Full note on SAP: SAP Support Launchpad note 2814007
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
