SAP security note 1909665, "Untrusted XML input parsing possible in CA-WUI-UI-TAG". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can modify an XML-based request to include XML content that is then parsed locally. This could allow a malicious user to perform a denial of service (DoS) on the parsing system, disclose local data that is returned in the response to the malicious request, or access further network-located resources accessible from the parsing system.
Solution
Install the attached correction instructions or the corresponding Support Package relevant to your software component version.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
References
- 1594475 – Potential denial of service in all programs using iXML
- 1712860 – iXML: Protection against attacks via a DTD
Affected components
- CRMUIF 600
- WEBCUIF 700, 701, 730, 731, 746, 747
- SAP_BASIS 640 to 730
Full note on SAP: SAP Support Launchpad note 1909665
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




