CVE-2015-1309: Medium severity sap netweaver as abap vulnerability
XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers to access arbitrary files via a crafted XML request, related to ECATTDISPLAYXMLSTRINGREMOTE, aka SAP Note 2016638.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1309?
CVE-2015-1309 is classified as a high severity vulnerability due to its potential for remote file access.
How do I fix CVE-2015-1309?
To mitigate CVE-2015-1309, you should upgrade to SAP NetWeaver AS ABAP 7.32 or later.
What is the impact of CVE-2015-1309 on SAP NetWeaver AS ABAP?
The impact of CVE-2015-1309 includes unauthorized access to arbitrary files on the server through crafted XML requests.
Which versions of SAP are affected by CVE-2015-1309?
CVE-2015-1309 affects SAP NetWeaver AS ABAP versions up to 7.31 inclusive.
Who can exploit CVE-2015-1309?
Remote attackers can exploit CVE-2015-1309 by sending specially crafted XML requests to an affected SAP NetWeaver instance.