PT-2018-1589 · Sap · Sap Netweaver
Published
2018-09-11
·
Updated
2018-11-26
·
CVE-2018-2462
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver BI versions 7.30 through 7.50
Description
The issue is related to the BEx Web Java Runtime Export Web Service in SAP NetWeaver BI, which does not sufficiently validate an XML document accepted from an untrusted source. This is due to incorrect restriction of XML links to external objects, allowing a remote attacker to potentially gain access to the file system or cause a denial of service.
Recommendations
For SAP NetWeaver BI versions 7.30 through 7.50, consider restricting access to the BEx Web Java Runtime Export Web Service until a fix is available, and ensure proper validation of XML documents from untrusted sources to prevent potential exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Netweaver