Skip links

Untrusted XML Input parsing possible in iXML applications, SAP security note 1744122

Description

A malicious user can modify an XML-based request to include XML content which is then parsed locally. This could allow a malicious user to perform a denial of service on the parsing system, or disclose local data which is then returned in the response to the malicious request.

Available fix and Supported packages

  • SAP_BASIS | 640 | 640
  • SAP_BASIS | 700 | 702
  • SAP_BASIS | 710 | 730
  • SAP_BASIS | 731 | 731

Affected component

    BC-ABA-XML
    ABAP XML processing

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1744122

TAGS

#Information-disclosure
#Denial-of-Service
#XXE
#iXML
#XSLT

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer

Initiating SAP Penetration Testing

►   Pentest, short for penetration testing, refers to a set of processes that simulate an attacker’s actions to identify security vulnerabilities. Companies