Lucene search

K
cve[email protected]CVE-2015-2812
HistoryApr 01, 2015 - 2:59 p.m.

CVE-2015-2812

2015-04-0114:59:11
web.nvd.nist.gov
19
cve-2015-2812
xxe
sap
netweaver portal
security vulnerability
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.7 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.9%

XML external entity (XXE) vulnerability in XMLValidationComponent in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2093966.

Affected configurations

NVD
Node
sapnetweaver_enterprise_portalMatch7.31

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.7 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.9%