First published: Sat Oct 19 2013(Updated: )
The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to read arbitrary files via a SQL statement containing an XML document with an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Sybase Adaptive Server Enterprise | =15.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6025 is considered a medium severity vulnerability due to its potential to allow unauthorized file access.
To mitigate CVE-2013-6025, upgrade to a non-affected version of SAP Sybase Adaptive Server Enterprise that is compliant with security updates.
CVE-2013-6025 allows remote authenticated users to read arbitrary files on the server, which could lead to sensitive information disclosure.
Users of SAP Sybase Adaptive Server Enterprise 15.7 ESD 2 are affected by CVE-2013-6025.
Yes, CVE-2013-6025 can be exploited remotely as it affects authenticated users executing SQL statements.