First published: Thu Jan 22 2015(Updated: )
XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers to access arbitrary files via a crafted XML request, related to ECATT_DISPLAY_XMLSTRING_REMOTE, aka SAP Note 2016638.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS for ABAP | <=7.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1309 is classified as a high severity vulnerability due to its potential for remote file access.
To mitigate CVE-2015-1309, you should upgrade to SAP NetWeaver AS ABAP 7.32 or later.
The impact of CVE-2015-1309 includes unauthorized access to arbitrary files on the server through crafted XML requests.
CVE-2015-1309 affects SAP NetWeaver AS ABAP versions up to 7.31 inclusive.
Remote attackers can exploit CVE-2015-1309 by sending specially crafted XML requests to an affected SAP NetWeaver instance.