Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
(AV:N/AC:L/AU:S/C:P/I:N/A:NSAP)
Производитель ПО
Наименование ПО
SAP Notes
(1820894-6)
SAP Support Packages
(SOFTWARE_LIFECYCLE_730_SP010_000000, SOFTWARE_LIFECYCLE_730_SP999999_999999, SOFTWARE_LIFECYCLE_731_SP006_000001, SOFTWARE_LIFECYCLE_731_SP007_000000, SOFTWARE_LIFECYCLE_731_SP008_000000, SOFTWARE_LIFECYCLE_731_SP999999_999999, SOFTWARE_LIFECYCLE_740_SP002_000000, SOFTWARE_LIFECYCLE_740_SP003_000000, SOFTWARE_LIFECYCLE_740_SP999999_999999)
Описание
The problem is caused by a program error in SLM due to the incorrect use of an XML parser. By default, the parser opens external entities referenced within an XML input, which can then lead to malicious content being parsed. This malicious content can reference internal resources, such as files. These internal resources can be disclosed in the response to the request, or can be used to perform a denial of service attack on the parsing system, rending application content temporarily unavailable.
Как исправить
Apply the appropriate patch of component SWLIFECYCL: NW 7.30 SP 10 or later NW 7.31 SP6 Patch 1 NW 7.31 SP7 or later NW 7.40 SP3 or later
Ссылки