[ERPSCAN-17-004] SAP NetWeaver Java 7.5 XXE

Application: SAP NetWeaver
Versions Affected: SAP NetWeaver 7.5
Vendor URL: SAP
Bugs: XXE
Reported: 17.06.2016
Vendor response: 18.06.2016
Date of Public Advisory: 10.01.2017
Reference: SAP Security Note 2347439
Author: Mathieu Geli (ERPScan)

VULNERABILITY INFORMATION

Class: XXE
Impact: Denial of Service, Read File
Remotely Exploitable: Yes
Locally Exploitable: No

CVSS Information

CVSS Base Score v3: 6.4 / 10
CVSS Base Vector:

AV: Attack Vector (Related exploit range) Network (N)
AC: Attack Complexity (Required attack complexity) High (H)
PR: Privileges Required (Level of privileges needed to exploit) Low (L)
UI: User Interaction (Required user participation) None (N)
S: Scope (Change in scope due to impact caused to components beyond the vulnerable component) Unchanged (U)
C: Impact to Confidentiality Low (L)
C: Impact to Integrity Low (L)
A: Impact to Availability High (H)

Description

A malicious user can modify an XML-based request to include XML content that is then parsed locally.

Business risk

An attacker can use an XML external entity vulnerability to send specially crafted unauthorized XML requests which will be processed by XML parser. The attacker can use the XML external entity vulnerability for getting an unauthorized access to OS filesystem.

VULNERABLE PACKAGES

VISUAL COMPOSER 7.0 RT 7.30
VISUAL COMPOSER 7.0 RT 7.31
VISUAL COMPOSER 7.0 RT 7.40
VISUAL COMPOSER FRAMEWORK 7.00
VISUAL COMPOSER FRAMEWORK 7.01
VISUAL COMPOSER FRAMEWORK 7.02

SOLUTIONS AND WORKAROUNDS

To correct this vulnerability, install SAP Security Note 2347439 .

TECHNICAL DESCRIPTION

Proof of Concept