Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Untrusted XML input parsing possible in the runtime of SAP NetWeaver Business Client, SAP security note 2183189

SAP Note 2183189

SAP security note 2183189, "Untrusted XML input parsing possible in the runtime of SAP NetWeaver Business Client", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A vulnerability has been identified in the runtime of SAP NetWeaver Business Client (NWBC) that allows a malicious user to modify an XML-based request to include untrusted XML content. This flaw can lead to denial of service (DoS) attacks, data disclosure, or unauthorized access to additional network resources accessible from the parsing system.

Solution

To mitigate this vulnerability, import the corrections provided in SAP Security Note 2183189.

CVSS

Score 4.9 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:P

References

Affected components

  • UI2_FND: Version 100
  • SAP_UI: Version 740
  • SAP_BASIS: Versions 700-702, 711, 730, 731

Full note on SAP: SAP Support Launchpad note 2183189

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More