SAP security note 2847787, “[CVE-2020-6202] Missing XML Validation in SAP NetWeaver Application Server Java (User Management Engine)”. Below are the symptom and SAP recommended solution.
Description
Symptom
The User Management Engine (UME) does not sufficiently validate the LDAP datasource configuration XML document accepted from an untrusted source.
Impacts:
- Denial-of-Service conditions in successful exploits
Solution
The corrective measure provided with this note ensures the LDAP datasource configuration XML document is properly validated.
CVSS
Score 5.5 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L
Full note on SAP: SAP Support Launchpad note 2847787
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
