Vulnerability Name: | CVE-2013-6244 (CCN-88265) | ||||||||
Assigned: | 2013-10-23 | ||||||||
Published: | 2013-10-23 | ||||||||
Updated: | 2013-10-31 | ||||||||
Summary: | The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWeaver 7.31 and earlier allows remote attackers to read arbitrary files and directories via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-6244 Source: CCN Type: PT-2013-13 XML External Entities Injection in SAP NetWeaver Source: MISC Type: UNKNOWN http://en.securitylab.ru/lab/PT-2013-13 Source: OSVDB Type: UNKNOWN 98892 Source: CONFIRM Type: UNKNOWN http://scn.sap.com/docs/DOC-8218 Source: CCN Type: SA55302 SAP NetWeaver Live Update XML External Entities Information Disclosure Vulnerability Source: SECUNIA Type: Vendor Advisory 55302 Source: CCN Type: OSVDB ID: 98892 SAP NetWeaver /webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP XML External Entity (XXE) Data Handling Arbitrary File Disclosure Source: BID Type: UNKNOWN 63302 Source: CCN Type: BID-63302 SAP NetWeaver Web Dynpro Live Update XML External Entity Information Disclosure Vulnerability Source: XF Type: UNKNOWN sap-netweaver-cve20136244-info-disc(88265) Source: CCN Type: SAP Web site SAP Security Note 1820894 Source: MISC Type: UNKNOWN https://service.sap.com/sap/support/notes/1820894 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |