Code Injection via XSL Transformation Servlet (IllumXSLTServlet) in SAP MII
SAP Manufacturing Integration and Intelligence (MII)
Two critical code injection notes in MII in a single month (plus four more MII notes at lower severities) makes MII the product of the month for all the wrong reasons. Apply Notes 3765948 and 3758900 together in a single MII maintenance window.
Vulnerability Detail
A second code injection vulnerability in SAP Manufacturing Integration and Intelligence affects the IllumXSLTServlet component, which was susceptible to server-side template injection (SSTI). A highly privileged attacker can supply a malicious XSL template that causes the servlet to execute arbitrary operating system commands on the MII host. SAP removed the vulnerable servlet as part of the remediation.
Workaround
Restrict access to the IllumXSLTServlet endpoint via WAF or application-level controls as a temporary measure.
Patch Action
Apply SAP Note 3758900. Bundle with Note 3765948 — both address MII code injection and affect the same versions.
Affected Versions
Patch Info