SAML 2.0 functionality in SAP NetWeaver AS Java, does not...
High severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Dec 11, 2018
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 1, 2023
SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. This is fixed in versions 7.2, 7.30, 7.31, 7.40 and 7.50.
References