SAP Security Note
Medium priority
SAP security note 2457269, "Missing XML Validation vulnerability in Business Planning & Consolidation system reports", is a program error note released on 13.06.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
The Business Planning & Consolidation System Report does not sufficiently validate an XML document accepted from an untrusted source.
Impacts of Missing XML Validation Vulnerability:
- Arbitrary file retrieval from the server
- Denial-of-service conditions in successful exploits
Solution
Please perform the following steps:
- Apply the latest kernel patch for your system (or at least a kernel patch level as mentioned in SAP Note 1594475).
- Apply the program corrections of SAP Note 1712860 or upgrade to the corresponding Support Package.
- Apply the program corrections of this SAP Note, or upgrade to the corresponding Support Package.
CVSS
Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References
This note refers to
- SAP Note 2423841 – SAP BusinessObjects Planning & Consolidation 10.1 on SAP NW 7.5 SP08 Central Note
- SAP Note 2415011 – SAP Business Planning & Consolidation 10.1 NW SP13 Central Note
- SAP Note 2378129 – Business Planning & Consolidation 10.0 NW SP24 Central Note
- SAP Note 2376449 – SAP Business Planning and Consolidation 10.1, version for S/4HANA 1610 Central Note
- SAP Note 1712860 – iXML: Protection against attacks via a DTD
- SAP Note 1594475 – Potential denial of service in all programs using iXML
Full note on SAP: SAP Support Launchpad note 2457269
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



