CVE-2015-2812: Medium severity sap netweaver (enterprise portal) vulnerability
Published Apr 1, 2015
·Updated
XML external entity (XXE) vulnerability in XMLValidationComponent in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2093966.
Affected Software
1 affected component
SAP NetWeaver Enterprise Portal=7.31
Event History
Apr 1, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2812?
CVE-2015-2812 is considered to be a high severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2015-2812?
To fix CVE-2015-2812, apply the patches provided in SAP Security Note 2093966 as soon as possible.
3
Who is affected by CVE-2015-2812?
CVE-2015-2812 affects users of SAP NetWeaver Portal version 7.31.
4
What kind of attack does CVE-2015-2812 allow?
CVE-2015-2812 allows remote attackers to send crafted XML requests, potentially accessing internal servers.
5
Is CVE-2015-2812 an XML external entity (XXE) vulnerability?
Yes, CVE-2015-2812 is classified as an XML external entity (XXE) vulnerability.