SAP Security Note
High priority
SAP security note 1756978, “SAML 2.0: possible XML signature wrapping attack”, is a program error note released on 11.09.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Messages sent and received by the SAML 2.0 Service Provider can be manipulated by a malicious user to allow them to perform unauthorised actions on behalf of another user, thereby generally circumventing the integrity protection provided by the service.
Solution
Update your SAP HANA to revision 36 or later.
Reason and prerequisites
The SAML 2.0 Service Provider implementation contains a vulnerability in the manner in which XML signatures are used to certify security assertions. This issue affects multiple vendors of SAML 2.0 implementations, and is not SAP specific. A malicious user can intercept or issue one signed assertion, and use an XML signature wrapping attack to gain higher privileges or impersonate another user. This means that there is a risk of information disclosure, data tampering and system unavailability as a result of this vulnerability.
CVSS
Score 0
References
This note refers to
Affected components
- HDB: 1.00 to 1.00
Full note on SAP: SAP Support Launchpad note 1756978
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




