SAP security note 2125358, "XXE Vulnerability in SAP Mobile Platform". Below are the symptom and SAP recommended solution.
Description
Symptom
Older versions of the UAFAgent used for administering SAP Mobile Platform (SMP) Servers had open URLs for inherited functionality from the UAF Agent framework. These exposed endpoints could be exploited by attackers to perform XML External Entity (XXE) attacks, leading to information disclosure or denial of service (DoS).
Solution
- SMP 2.2: Upgrade to SMP 2.2 SP06 PL02
- SMP 2.3: Upgrade to SMP 2.3 SP05 PL01
Reason and prerequisites
The vulnerability is caused by a program error in the ‘ValidationComponent’ due to the incorrect use of an XML parser. By default, the parser opens external entities referenced within an XML input, allowing malicious content to be parsed. This can lead to the disclosure of internal resources or perform a DoS attack on the parsing system.
CVSS
Score 6.4 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P
Full note on SAP: SAP Support Launchpad note 2125358
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
