SAP NetWeaver CCMS Service XML Parser Information Disclosure Vulnerability
BID:57654
Info
SAP NetWeaver CCMS Service XML Parser Information Disclosure Vulnerability
| Bugtraq ID: | 57654 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2013 12:00AM |
| Updated: | Jan 31 2013 12:00AM |
| Credit: | Alexey Tyurin of ERPScan |
| Vulnerable: |
SAP Web Application Server 7.0.10 SAP Web Application Server 7.0 SAP NetWeaver 7.30 SAP NetWeaver 7.10 SAP NetWeaver 7.02 SAP NetWeaver 7.01 SAP NetWeaver 7.0 |
| Not Vulnerable: | |
Discussion
SAP NetWeaver CCMS Service XML Parser Information Disclosure Vulnerability
SAP NetWeaver is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks.
SAP NetWeaver is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks.
Exploit / POC
SAP NetWeaver CCMS Service XML Parser Information Disclosure Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
SAP NetWeaver CCMS Service XML Parser Information Disclosure Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.