SAP Security Note
SAP security note 1530454, "MDX: XML injection when an XMLA interface is used", is a note released on 10.01.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can use the XMLA interface to add new attributes to an XML element. However, currently no possibilities are known whereby the system availability, data confidentiality, or data integrity is at risk.
Solution
- SAP NetWeaver BW 7.00: Import Support Package 26 (SAPKW70026) into your BW system. Refer to SAP Note 1524896 for more details.
- SAP NetWeaver BW 7.01: Import Support Package 09 (SAPKW70109) into your BW system. Refer to SAP Note 1369296 for more details.
- SAP NetWeaver BW 7.02: Import Support Package 08 (SAPKW70208) into your BW system. Refer to SAP Note 1510975 for more details.
- SAP NetWeaver BW 7.11: Import Support Package 07 (SAPKW71107) into your BW system. Refer to SAP Note 1510976 for more details.
- SAP NetWeaver BW 7.30: Import Support Package 03 (SAPKW73003) into your BW system. Refer to SAP Note 1538941 for more details.
In urgent cases, you can implement the correction instructions as an advance correction. You must first read Note 875986, which provides information about transaction SNOTE.
Reason and prerequisites
There is a program error. When a test page is created, the system does not check whether unexpected attributes are used.
CVSS
Score 0
References
- Briefing at Black Hat conference on July 31st, 2013
- MDX: XML for Analysis – known security holes
- SAPBINews NW BW 7.00 ABAP SP 26
- SAPBINews NW BW 7.11 ABAP SP 07
- SAPBINews NW BW 7.02 ABAP SP 07
- SAPBINews NW BW 7.30 ABAP SP 02
- SAPBINews NW BW 7.01 ABAP SP 09
- Automatic checks for security notes using RSECNOTE (outdated)
Full note on SAP: SAP Support Launchpad note 1530454
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




