{"api_version":"1","generated_at":"2026-07-23T08:57:20+00:00","cve":"CVE-2013-3617","urls":{"html":"https://cve.report/CVE-2013-3617","api":"https://cve.report/api/cve/CVE-2013-3617.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-3617","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-3617"},"summary":{"title":"CVE-2013-3617","description":"The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.","state":"PUBLISHED","assigner":"certcc","published_at":"2013-11-02 19:55:04","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/533894","name":"http://www.kb.cert.org/vuls/id/533894","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","US Government Resource"],"title":"VU#533894 - Openbravo ERP contains an information disclosure vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/63431","name":"http://www.securityfocus.com/bid/63431","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Openbravo ERP  CVE-2013-3617 XML External Entity Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats","name":"https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Metasploit: Seven FOSS Tricks and Treats (Part ... | SecurityStreet","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-3617","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-3617","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"3617","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openbravo","cpe5":"openbravo_erp","cpe6":"2.40","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"3617","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openbravo","cpe5":"openbravo_erp","cpe6":"2.50","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"3617","vulnerable":"1","versionEndIncluding":"3.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openbravo","cpe5":"openbravo_erp","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T16:14:56.605Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats"},{"name":"VU#533894","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/533894"},{"name":"63431","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/63431"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2013-11-02T19:00:00.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"tags":["x_refsource_MISC"],"url":"https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats"},{"name":"VU#533894","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/533894"},{"name":"63431","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/63431"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2013-3617","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats","refsource":"MISC","url":"https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats"},{"name":"VU#533894","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/533894"},{"name":"63431","refsource":"BID","url":"http://www.securityfocus.com/bid/63431"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2013-3617","datePublished":"2013-11-02T19:00:00.000Z","dateReserved":"2013-05-21T00:00:00.000Z","dateUpdated":"2024-09-17T02:36:55.070Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-11-02 19:55:04","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openbravo:openbravo_erp:*:*:*:*:*:*:*:*","versionEndIncluding":"3.0","matchCriteriaId":"856429C7-7977-45DF-BA55-A319C87F22E3"},{"vulnerable":true,"criteria":"cpe:2.3:a:openbravo:openbravo_erp:2.40:*:*:*:*:*:*:*","matchCriteriaId":"36E5C029-509F-4005-B428-AC35F16F8A91"},{"vulnerable":true,"criteria":"cpe:2.3:a:openbravo:openbravo_erp:2.50:*:*:*:*:*:*:*","matchCriteriaId":"0C864621-1CB9-4753-A184-3CD65FD01CFD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"3617","Ordinal":"1","Title":"CVE-2013-3617","CVE":"CVE-2013-3617","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"3617","Ordinal":"1","NoteData":"The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.","Type":"Description","Title":"CVE-2013-3617"},{"CveYear":"2013","CveId":"3617","Ordinal":"2","NoteData":"2013-11-02","Type":"Other","Title":"Published"}]}}}