CVE-2015-4091
 
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
XML external entity (XXE) vulnerability in SAP NetWeaver AS Java 7.4 allows remote attackers to send TCP requests to intranet servers or possibly have unspecified other impact via an XML request to tc~sld~wd~main/Main, related to "CIM UPLOAD," aka SAP Security Note 2090851.
Vulnerabilidad de XXE en SAP NetWeaver AS Java 7.4 permite a atacantes remotos enviar peticiones TCP a servidores intranet o posiblemente tener otro impacto no especificado a través de una petición XML a tc~sld~wd~main/Main, relacionado con "CIM UPLOAD", también conocida como SAP Security Note 2090851.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2015-05-26 CVE Reserved
- 2015-05-26 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/133122/SAP-NetWeaver-AS-Java-XXE-Injection.html | X_refsource_misc | |
http://seclists.org/fulldisclosure/2015/May/96 | Mailing List | |
http://www.securityfocus.com/archive/1/536239/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/74850 | Vdb Entry | |
https://erpscan.io/advisories/erpscan-15-013-sap-netweaver-as-java-cim-upload-xxe | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Sap Netweaver Application Server Java Search vendor "Sap" for product "Sap Netweaver Application Server Java" | 7.4 Search vendor "Sap" for product "Sap Netweaver Application Server Java" and version "7.4" | - |
Affected
|