Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing XML Validation vulnerability in TranslationSupport application, SAP security note 2400292

SAP Note 2400292

SAP security note 2400292, "Missing XML Validation vulnerability in TranslationSupport application". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A vulnerability has been identified in the TranslationSupport application, which is part of the Composite Application Framework (CAF). The application does not sufficiently validate XML documents received from untrusted sources, potentially allowing attackers to retrieve arbitrary files from the server or cause denial-of-service (DoS) conditions.

Solution

The TranslationSupport application has been removed to address this vulnerability. It is recommended to implement the Support Packages and Patches referenced in this SAP Note.

CVSS

Score 5.4 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

References

Affected components

  • Composite Application Framework (CAF), versions 7.11 to 7.50

Full note on SAP: SAP Support Launchpad note 2400292

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More