SAP security note 2111939, "XML External Entity vulnerability in SAP XML Parser". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can modify an XML-based request to include XML content that is parsed locally by the SAP XML Parser. This vulnerability could allow an attacker to:
- Perform a denial of service (DoS) attack on the parsing system.
- Disclose local data returned in the response to the malicious request.
- Access further network-located resources accessible from the parsing system.
Solution
To address this vulnerability, check for the appropriate Support Package (SP) and Patch levels that fix the issue under the "Support Packages & Patches" tab within this note.
CVSS
Score 5.5 Vector: Network (N)/Low (L)/Single (S)/Partial (P)/None (N)/Partial (P)
References
- 2116602 – Central Note for Portal Platform in SAP NW7.1 SP20
- 2116600 – Central Note for Portal Platform in SAP NW7.1 EhP1 SP15
- 2110834 – Central Note for Portal Platform in SAP NW7.0 EhP1 SP18
- 2110779 – Central Note for Portal Platform in SAP NW7.0 SP33
- 2086444 – Central Note for NetWeaver 7.40 SP11 EP / EPC
Affected components
- EP-PSERV: 7.00 to 7.02
- EP-RUNTIME: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40
Full note on SAP: SAP Support Launchpad note 2111939
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




