PT-2018-1589 · Sap · Sap Netweaver

Published

2018-09-11

·

Updated

2018-11-26

·

CVE-2018-2462

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP NetWeaver BI versions 7.30 through 7.50
Description The issue is related to the BEx Web Java Runtime Export Web Service in SAP NetWeaver BI, which does not sufficiently validate an XML document accepted from an untrusted source. This is due to incorrect restriction of XML links to external objects, allowing a remote attacker to potentially gain access to the file system or cause a denial of service.
Recommendations For SAP NetWeaver BI versions 7.30 through 7.50, consider restricting access to the BEx Web Java Runtime Export Web Service until a fix is available, and ensure proper validation of XML documents from untrusted sources to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01146
CVE-2018-2462

Affected Products

Sap Netweaver