Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6202 Missing XML Validation in SAP NetWeaver Application Server Java (User Management Engine), SAP security note 2847787

SAP Note 2847787

SAP security note 2847787, “[CVE-2020-6202] Missing XML Validation in SAP NetWeaver Application Server Java (User Management Engine)”. Below are the symptom and SAP recommended solution.

Description

Symptom

The User Management Engine (UME) does not sufficiently validate the LDAP datasource configuration XML document accepted from an untrusted source.

Impacts:

  • Denial-of-Service conditions in successful exploits

Solution

The corrective measure provided with this note ensures the LDAP datasource configuration XML document is properly validated.

CVSS

Score 5.5 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L

Full note on SAP: SAP Support Launchpad note 2847787

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More