Lucene search

K
cve[email protected]CVE-2013-6815
HistoryNov 20, 2013 - 2:12 p.m.

CVE-2013-6815

2013-11-2014:12:30
CWE-20
web.nvd.nist.gov
70
sap
netweaver
7.31
vulnerability
shsti_upload_xml
denial of service
xxe
nvd
cve-2013-6815

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.9 Medium

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.8%

The SHSTI_UPLOAD_XML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and earlier allows remote attackers to cause a denial of service via unspecified vectors, related to an XML External Entity (XXE) issue.

Affected configurations

NVD
Node
sapnetweaverRange7.31
OR
sapnetweaverMatch4.0
OR
sapnetweaverMatch6.4
OR
sapnetweaverMatch7.0
OR
sapnetweaverMatch7.0ehp1
OR
sapnetweaverMatch7.0ehp2
OR
sapnetweaverMatch7.0sp15
OR
sapnetweaverMatch7.0sp8
OR
sapnetweaverMatch7.01
OR
sapnetweaverMatch7.02
OR
sapnetweaverMatch7.03
OR
sapnetweaverMatch7.10
OR
sapnetweaverMatch7.30

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.9 Medium

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.8%

Related for CVE-2013-6815