[ERPSCAN-15-013] SAP NetWeaver AS Java CIM UPL OAD – XXE

Posted by ERPScan inc on Aug 18

ERPSCAN Research Advisory [ERPSCAN-15-013] SAP NetWeaver AS Java CIM
UPLOAD – XXE

Application: SAP NetWeaver AS Java
Versions Affected: SAP NetWeaver AS Java 7.4, probably others
Vendor URL: http://SAP.com
Bugs: XML External Entity
Sent: 16.06.2014
Reported: 17.06.2014
Vendor response: 17.06.2014
Date of Public Advisory: 17.08.2015
Reference: SAP Security Note 2090851
Author: Vahagn Vardanyan…

Leave a Reply