Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6315 Multiple Vulnerabilities in SAP 3D Visual Enterprise Viewer, SAP security note 2973497

SAP Note 2973497

SAP security note 2973497, “[CVE-2020-6315] Multiple Vulnerabilities in SAP 3D Visual Enterprise Viewer”. Below are the symptom and SAP recommended solution.

Description

Symptom

This SAP security note addresses several vulnerabilities identified in SAP 3D Visual Enterprise Viewer. The vulnerability details along with their CVE relevant information can be found below.

1. Information Disclosure. An attacker can send a manipulated file to the victim, which can lead to the leakage of sensitive information when the victim loads the malicious file into SAP 3D VE viewer. CVE-2020-6315, CVSS Score 5.7, Vector CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N.

2. Improper Input Validation. When a user opens manipulated files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until the application is restarted.

The file format details along with their CVE relevant information can be found below:

  • Right Hemisphere Binary (.rh) – CVE-2020-6376
  • Computer Graphics Metafile (.cgm) – CVE-2020-6375
  • Jupiter Tessellation (.jt) – CVE-2020-6374
  • Portable Document Format (.pdf) – CVE-2020-6373
  • Portable Document Format (.pdf) – CVE-2020-6372

CVSS Score 4.3, Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L.

Solution

Resolution of external DTD entities was disabled by default. Fixes for all linked CVE-IDs are comprised in the same SP Patch level.

The following file formats have been fixed with additional validation when they are opened in SAP 3D Visual Enterprise Viewer:

  • Computer Graphics Metafile (.cgm)
  • Jupiter Tessellation (.jt)
  • Portable Document Format (.pdf)
  • Right Hemisphere Binary (.rh)

SAP Note 2949173 provides release information about SAP 3D Visual Enterprise Viewer 9.0 FP09 MP3.

Reason and prerequisites

Information Disclosure: External DTD entities in SVG files are not checked.

Insufficient input validation when the above-mentioned file formats are opened in SAP 3D Visual Enterprise Viewer.

CVSS

Score 5.7 Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Full note on SAP: SAP Support Launchpad note 2973497

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More