Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing XML Validation vulnerability in Business Planning & Consolidation system reports, SAP security note 2457269

SAP Note 2457269
SAP Security Note
Medium priority

SAP security note 2457269, "Missing XML Validation vulnerability in Business Planning & Consolidation system reports", is a program error note released on 13.06.2017. Below are the symptom and SAP recommended solution.

ComponentEnterprise Performance Management > Business Planning and Consolidation > NetWeaver Version > Audit Reports
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on13.06.2017
LanguageEnglish

Description

Symptom

The Business Planning & Consolidation System Report does not sufficiently validate an XML document accepted from an untrusted source.

Impacts of Missing XML Validation Vulnerability:

  • Arbitrary file retrieval from the server
  • Denial-of-service conditions in successful exploits

Solution

Please perform the following steps:

  • Apply the latest kernel patch for your system (or at least a kernel patch level as mentioned in SAP Note 1594475).
  • Apply the program corrections of SAP Note 1712860 or upgrade to the corresponding Support Package.
  • Apply the program corrections of this SAP Note, or upgrade to the corresponding Support Package.

CVSS

Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

References

This note refers to

  • SAP Note 2423841 – SAP BusinessObjects Planning & Consolidation 10.1 on SAP NW 7.5 SP08 Central Note
  • SAP Note 2415011 – SAP Business Planning & Consolidation 10.1 NW SP13 Central Note
  • SAP Note 2378129 – Business Planning & Consolidation 10.0 NW SP24 Central Note
  • SAP Note 2376449 – SAP Business Planning and Consolidation 10.1, version for S/4HANA 1610 Central Note
  • SAP Note 1712860 – iXML: Protection against attacks via a DTD
  • SAP Note 1594475 – Potential denial of service in all programs using iXML

Full note on SAP: SAP Support Launchpad note 2457269

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More