SAP security note 1729293, "Untrusted XML input parsing possible in GRMG". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can modify an XML-based response to include XML content that is then parsed locally. This vulnerability could allow an attacker to perform a denial of service (DoS) on the parsing system or access additional network-located resources accessible from the parsing system.
Solution
Implement the appropriate support package or the correction instruction provided in this note. If opting for the correction instruction, ensure that Note 1594475 is implemented beforehand, requiring your system to be at least at the support package level specified in that note.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
References
- 1594475 – Potential denial of service in all programs using iXML
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- BC-CCM-MON (Basis Components > Computer Center Management System (CCMS) > CCMS Monitoring & Alerting)
Full note on SAP: SAP Support Launchpad note 1729293
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
