SAP NetWeaver Process Integration XML External Entity Information Disclosure Vulnerability
BID:56316
Info
SAP NetWeaver Process Integration XML External Entity Information Disclosure Vulnerability
| Bugtraq ID: | 56316 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2012 12:00AM |
| Updated: | Oct 22 2012 12:00AM |
| Credit: | Alexander Polyakov, Alexey Tyurin, and Alexandr Minozhenko of ERPScan. |
| Vulnerable: |
SAP NetWeaver Process Integration 7.0 |
| Not Vulnerable: | |
Discussion
SAP NetWeaver Process Integration XML External Entity Information Disclosure Vulnerability
SAP NetWeaver Process Integration is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks.
SAP NetWeaver Process Integration is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks.
Exploit / POC
SAP NetWeaver Process Integration XML External Entity Information Disclosure Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
SAP NetWeaver Process Integration XML External Entity Information Disclosure Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
SAP NetWeaver Process Integration XML External Entity Information Disclosure Vulnerability
References:
References: