SAP security note 2400292, "Missing XML Validation vulnerability in TranslationSupport application". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A vulnerability has been identified in the TranslationSupport application, which is part of the Composite Application Framework (CAF). The application does not sufficiently validate XML documents received from untrusted sources, potentially allowing attackers to retrieve arbitrary files from the server or cause denial-of-service (DoS) conditions.
Solution
The TranslationSupport application has been removed to address this vulnerability. It is recommended to implement the Support Packages and Patches referenced in this SAP Note.
CVSS
Score 5.4 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
References
Affected components
- Composite Application Framework (CAF), versions 7.11 to 7.50
Full note on SAP: SAP Support Launchpad note 2400292
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
