CVE-2013-3617
Summary
| CVE | CVE-2013-3617 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-11-02 19:55:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openbravo | Openbravo Erp | 2.40 | All | All | All |
| Application | Openbravo | Openbravo Erp | 2.50 | All | All | All |
| Application | Openbravo | Openbravo Erp | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VU#533894 - Openbravo ERP contains an information disclosure vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Exploit, US Government Resource |
| Openbravo ERP CVE-2013-3617 XML External Entity Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| Metasploit: Seven FOSS Tricks and Treats (Part ... | SecurityStreet | af854a3a-2127-422b-91ae-364da2661108 | community.rapid7.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.