CVE-2013-6244: Medium severity SAP NetWeaver vulnerability
The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~uilup/LUP) in SAP NetWeaver 7.31 and earlier allows remote attackers to read arbitrary files and directories via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6244?
CVE-2013-6244 has a high severity level due to its ability to allow remote attackers to read arbitrary files.
How do I fix CVE-2013-6244?
To fix CVE-2013-6244, it is recommended to apply the latest patches and updates from SAP for the affected versions of NetWeaver.
What versions of SAP NetWeaver are affected by CVE-2013-6244?
CVE-2013-6244 affects SAP NetWeaver versions 4.0, 6.4, and all versions up to 7.31.
What type of attack does CVE-2013-6244 enable?
CVE-2013-6244 enables a type of attack known as XML External Entity (XXE) attack.
Is user authentication required to exploit CVE-2013-6244?
No, CVE-2013-6244 can be exploited remotely without the need for user authentication.