SAP security note 1597066, "MDX: SOAP/XMLA Interface and Document Type Definitions". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can attempt to generate a "denial of service" situation or start an "SMB relay attack" using Document Type Definitions (DTD) via the SOAP/XMLA interface.
Solution
This correction prevents the use of Document Type Definitions when you use the SOAP/XMLA interface.
Reason and prerequisites
There is a program error. Document Type Definitions must not occur in SOAP requests.
CVSS
Score 4.0 Vector: AV:N/AC:L/AU:S/C:N/I:N/A:P
References
- SAP Note 1889488 – Briefing at Black Hat conference on July 31st, 2013
- SAP Note 1881391 – MDX: XML for Analysis – known security holes
- SAP Note 1665770 – SAPBWNews NW BW 7.11 ABAP SP10
- SAP Note 1665768 – SAPBWNews BW 7.01 ABAP SP12
- SAP Note 1658505 – SAPBWNews BW 7.00 ABAP SP29
- SAP Note 1652580 – SAPBWNews NW BW 7.31 ABAP SP03
- SAP Note 1652579 – SAPBWNews NW 7.30 BW ABAP SP07
- SAP Note 1641364 – SAPBWNews NW 7.02 BW ABAP SP11
Affected components
- SAP Business Warehouse > Business Explorer > OLAP Technology > MDX, OLAP-BAPI, OLE DB for OLAP
Full note on SAP: SAP Support Launchpad note 1597066
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
