Advisory
A note with CVSS 5.9 for component BC-DWB-AIE-DIC was released by SAP on 10.03.2020. The correction/advisory 2892570 was described with "Missing XML Validation vulnerability in ABAP Development Tools" and affects the system type ABAP Development Tools.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as project.
The vulnerability addressed is external entity tunneling (xxe) within ABAP Development Tools.
Risk specification
The 'Data Definition' editor in ABAP Development Tools (ABAP for Eclipse) does not sufficiently validate an XML document resulting in the code execution on the client.Solution
ABAP Development Tools no longer use the default XMLDecoder, instead a custom Content handler is used that properly valiidated the XML input.
The advisory is valid for
- SAP_BASIS_AIE 3
- 9.8 Potential XML External Entity Injection Vulnerability in SAP Environmental Compliance
- 9.6 [CVE-2020-26831] Missing XML Validation in SAP BusinessObjects Business Intelligence Platform (Crystal Report)
- 9.3 [CVE-2020-6238] Missing XML Validation vulnerability in SAP Commerce
- 8.7 [CVE-2021-27635] Missing XML Validation in SAP NetWeaver AS for JAVA
- 8.6 [CVE-2024-24743] XXE vulnerability in SAP NetWeaver AS Java (Guided Procedures)