PT-2019-4196 · Sap · Sap Netweaver Application Server Java
Published
2019-08-13
·
Updated
2019-08-23
·
CVE-2019-0345
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver Application Server for Java versions 7.30 through 7.50
Description
A remote unauthenticated attacker can exploit a web service in the SAP NetWeaver Application Server for Java by sending a specially crafted XML file. This can trick the application server into leaking authentication credentials for its own SAP Management console, resulting in Server-Side Request Forgery. The issue is related to insufficient request validation on the server side, which can allow an attacker to disclose privileged user credentials using the specially crafted XML file.
Recommendations
For versions 7.30 through 7.50, consider restricting access to the vulnerable web service until a patch is available.
As a temporary workaround, avoid using the web service in SAP NetWeaver Application Server for Java until the issue is resolved.
Restrict access to the SAP Management console to minimize the risk of exploitation.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver Application Server Java