Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

MDX XML injection when an XMLA interface is used, SAP security note 1530454

SAP Note 1530454
SAP Security Note

SAP security note 1530454, "MDX: XML injection when an XMLA interface is used", is a note released on 10.01.2012. Below are the symptom and SAP recommended solution.

ComponentSAP Business Warehouse > Business Explorer > OLAP Technology > MDX, OLAP-BAPI, OLE DB for OLAP
TypeSAP Security Note
StatusReleased for Customer
Released on10.01.2012

Description

Symptom

A malicious user can use the XMLA interface to add new attributes to an XML element. However, currently no possibilities are known whereby the system availability, data confidentiality, or data integrity is at risk.

Solution

  • SAP NetWeaver BW 7.00: Import Support Package 26 (SAPKW70026) into your BW system. Refer to SAP Note 1524896 for more details.
  • SAP NetWeaver BW 7.01: Import Support Package 09 (SAPKW70109) into your BW system. Refer to SAP Note 1369296 for more details.
  • SAP NetWeaver BW 7.02: Import Support Package 08 (SAPKW70208) into your BW system. Refer to SAP Note 1510975 for more details.
  • SAP NetWeaver BW 7.11: Import Support Package 07 (SAPKW71107) into your BW system. Refer to SAP Note 1510976 for more details.
  • SAP NetWeaver BW 7.30: Import Support Package 03 (SAPKW73003) into your BW system. Refer to SAP Note 1538941 for more details.

In urgent cases, you can implement the correction instructions as an advance correction. You must first read Note 875986, which provides information about transaction SNOTE.

Reason and prerequisites

There is a program error. When a test page is created, the system does not check whether unexpected attributes are used.

CVSS

Score 0

References

Full note on SAP: SAP Support Launchpad note 1530454

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More