SAP Security Note
Medium priority
SAP security note 2372301, "Missing XML Validation in Composite Application Framework Authorization Tool", is a note released on 02.11.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
UPDATE 2nd November: This note has been re-released with updated “Support Packages & Patches” information.
Composite Application Framework Authorization Tool launched from NetWeaver Administrator does not sufficiently validate an XML document when imported.
Some well-known impacts of Missing XML Validation vulnerability are:
- Arbitrary files retrieval from the server
- Denial-of-service conditions in successful exploits
Solution
The XML parser is now configured securely so that it does not allow external entities as part of an incoming XML document. Implement the Support Packages and Patches referenced by this SAP Note.
Full note on SAP: SAP Support Launchpad note 2372301
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
