Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SAP Mobile Platform XXE vulnarability, SAP security note 2125358

SAP Note 2125358

SAP security note 2125358, "XXE Vulnerability in SAP Mobile Platform". Below are the symptom and SAP recommended solution.

Description

Symptom

Older versions of the UAFAgent used for administering SAP Mobile Platform (SMP) Servers had open URLs for inherited functionality from the UAF Agent framework. These exposed endpoints could be exploited by attackers to perform XML External Entity (XXE) attacks, leading to information disclosure or denial of service (DoS).

Solution

  • SMP 2.2: Upgrade to SMP 2.2 SP06 PL02
  • SMP 2.3: Upgrade to SMP 2.3 SP05 PL01

Reason and prerequisites

The vulnerability is caused by a program error in the ‘ValidationComponent’ due to the incorrect use of an XML parser. By default, the parser opens external entities referenced within an XML input, allowing malicious content to be parsed. This can lead to the disclosure of internal resources or perform a DoS attack on the parsing system.

CVSS

Score 6.4 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Full note on SAP: SAP Support Launchpad note 2125358

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More