SAP NetWeaver AS Java CVE-2014-8590 XML External Entity Information Disclosure Vulnerability
BID:71023
Info
SAP NetWeaver AS Java CVE-2014-8590 XML External Entity Information Disclosure Vulnerability
| Bugtraq ID: | 71023 |
| Class: | Design Error |
| CVE: |
CVE-2014-8590 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2014 12:00AM |
| Updated: | Nov 11 2014 12:00AM |
| Credit: | Vahagn Vardanyan |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
SAP NetWeaver AS Java CVE-2014-8590 XML External Entity Information Disclosure Vulnerability
SAP NetWeaver is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information that may lead to further attacks.
SAP NetWeaver is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information that may lead to further attacks.
Exploit / POC
SAP NetWeaver AS Java CVE-2014-8590 XML External Entity Information Disclosure Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
References
SAP NetWeaver AS Java CVE-2014-8590 XML External Entity Information Disclosure Vulnerability
References:
References: