CVE-2017-11457: XEE
XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request, aka SAP Security Note 2387249.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11457?
CVE-2017-11457 is classified as a high-severity vulnerability due to its potential for data leakage and SSRF attacks.
How do I fix CVE-2017-11457?
To mitigate CVE-2017-11457, ensure that you apply the latest SAP patches and updates as recommended in SAP Security Note 2387249.
Who is affected by CVE-2017-11457?
CVE-2017-11457 affects SAP NetWeaver AS JAVA version 7.50 specifically when dealing with XML requests.
Can CVE-2017-11457 be exploited remotely?
Yes, CVE-2017-11457 can be exploited by remote authenticated users through specially crafted XML requests.
What kind of attacks can CVE-2017-11457 facilitate?
CVE-2017-11457 may allow attackers to read arbitrary files on the server or conduct server-side request forgery (SSRF) attacks.