First published: Tue Jul 25 2017(Updated: )
XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request, aka SAP Security Note 2387249.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Java Application Server | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11457 is classified as a high-severity vulnerability due to its potential for data leakage and SSRF attacks.
To mitigate CVE-2017-11457, ensure that you apply the latest SAP patches and updates as recommended in SAP Security Note 2387249.
CVE-2017-11457 affects SAP NetWeaver AS JAVA version 7.50 specifically when dealing with XML requests.
Yes, CVE-2017-11457 can be exploited by remote authenticated users through specially crafted XML requests.
CVE-2017-11457 may allow attackers to read arbitrary files on the server or conduct server-side request forgery (SSRF) attacks.