SAP security note 2026174, “SBOP solution for Apache Struts1.x Vulnerability CVE-2014-0094”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
UPDATE 24th November: This note has been re-released with updated CVSS details and Solution information.
The ParametersInterceptor in Apache Struts versions earlier than 2.3.16.3 allows remote attackers to manipulate the ClassLoader via the class parameter, which is passed to the getClass method. This vulnerability can be exploited to manipulate resources used to serve BI Launchpad, LCM, and Monitoring.
Solution
This vulnerability has been fixed by modifying configurations related to the Struts Framework. The fix has been delivered with the following updates:
- SAP BusinessObjects Enterprise XI3.1: Refer to the “Hotfix for XI3.1 FixPack 6.4” on the SAP Service Market Place.
- SAP BusinessObjects Enterprise XI3.1 FP7.1
- SAP BusinessObjects Enterprise XI4.0 FP8.9 and FP9.5
- SAP BusinessObjects Enterprise XI4.0 SP10
- SAP BusinessObjects Enterprise XI4.1 FP1.11, FP2.9, FP3.4, FP4.1
Reason and prerequisites
An attacker can infiltrate the application through vulnerabilities in the Struts framework, allowing malicious code injection to consume resources unnecessarily.
CVSS
Score 7.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
Affected components
- ENTERPRISE XI 3.1, 4.0, 410
Full note on SAP: SAP Support Launchpad note 2026174
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
