CVE-2013-6815: Input Validation
Published Nov 19, 2013
·Updated
The SHSTIUPLOADXML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and earlier allows remote attackers to cause a denial of service via unspecified vectors, related to an XML External Entity (XXE) issue.
Affected Software
13 affected components
SAP NetWeaver<=7.31
SAP NetWeaver=4.0
SAP NetWeaver=6.4
SAP NetWeaver=7.0
SAP NetWeaver=7.0-ehp1
SAP NetWeaver=7.0-ehp2
SAP NetWeaver=7.0-sp15
SAP NetWeaver=7.0-sp8
SAP NetWeaver=7.01
SAP NetWeaver=7.02
SAP NetWeaver=7.03
SAP NetWeaver=7.10
SAP NetWeaver=7.30
Event History
Nov 19, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Nov 20, 2013
Data Sourced
via NVD·02:12 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6815?
CVE-2013-6815 has a severity rating of medium due to its ability to cause a denial of service.
2
How do I fix CVE-2013-6815?
To fix CVE-2013-6815, ensure that you apply the latest patches provided by SAP for affected versions of SAP NetWeaver.
3
What versions of SAP NetWeaver are affected by CVE-2013-6815?
CVE-2013-6815 affects SAP NetWeaver versions 7.31 and earlier, including 4.0, 6.4, 7.0, and others.
4
Can CVE-2013-6815 be exploited remotely?
Yes, attackers can exploit CVE-2013-6815 remotely through unspecified vectors.
5
What is the impact of CVE-2013-6815 on SAP systems?
CVE-2013-6815 can lead to a denial of service condition, disrupting the normal operation of SAP systems.