Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6271 Missing XML Validation in SAP Solution Manager (Problem Context Manager), SAP security note 2931391

SAP Note 2931391
High

SAP security note 2931391, “[CVE-2020-6271] Missing XML Validation in SAP Solution Manager (Problem Context Manager)”, is a note released on June 9, 2020. Below are the symptom, SAP recommended solution and the affected software components.

PriorityHigh
StatusReleased for Customer
Released onJune 9, 2020

Description

Symptom

The Problem Context Manager application in SAP Solution Manager lacks necessary XML validation. This vulnerability allows an attacker to consume large amounts of memory, potentially causing the system to crash, and to achieve a minor loss of confidentiality.

Solution

The vulnerable feature is deprecated. To mitigate this issue, apply the latest LM-SERVICE patch, which deactivates the affected servlet. For detailed instructions, refer to SAP Note 2930617.

CVSS

Score 8.2 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

References

  • CVE-2020-6271

Affected components

  • SAP Solution Manager 7.20

Full note on SAP: SAP Support Launchpad note 2931391

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More