First published: Mon Mar 09 2020(Updated: )
nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Application Server | <2183189 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7968 has a medium severity rating due to its potential for XXE attacks that can lead to local file inclusion.
To fix CVE-2015-7968, you should upgrade SAP NetWeaver Application Server to a version that includes Security Note 2183189.
CVE-2015-7968 enables XML External Entity (XXE) attacks, allowing attackers to access local files on the server.
All versions of SAP NetWeaver Application Server prior to Security Note 2183189 are affected by CVE-2015-7968.
Yes, CVE-2015-7968 can compromise data security by allowing unauthorized access to sensitive local files on the server.