A malicious user can modify an XML-based request to include XML content which is then parsed locally. This could allow a malicious user to perform a denial of service on the parsing system, or disclose local data which is then returned in the response to the malicious request.
Available fix and Supported packages
- SAP_BASIS | 640 | 640
- SAP_BASIS | 700 | 702
- SAP_BASIS | 710 | 730
- SAP_BASIS | 731 | 731
ABAP XML processing
Exploit is not available.
For detailed information please contact the mail [email protected].