Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing XML Validation vulnerability in SAP Netweaver Log Viewer application, SAP security note 2372626

SAP Note 2372626

SAP security note 2372626, "Missing XML Validation Vulnerability in SAP NetWeaver Log Viewer". Below are the symptom and SAP recommended solution.

Description

Symptom

The Log Viewer application in SAP NetWeaver Administrator does not sufficiently validate an XML document accepted from an untrusted source. This Missing XML Validation vulnerability can lead to:

  • Arbitrary file retrieval from the server
  • Denial-of-Service (DoS) conditions in successful exploits

Solution

The XML parser is now configured securely to disallow external entities in incoming XML documents. To address this vulnerability:

  • Apply the Support Packages and Patches referenced in this SAP Note.
  • Enable the XML Hardener as described in the manual activities for this note.

CVSS

Score 5.5/10 Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L

References

Full note on SAP: SAP Support Launchpad note 2372626

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More