CVE-2017-8913: XEE
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtroot/com.sap.visualcomposer.BIKit.default, aka SAP Security Note 2386873.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8913?
CVE-2017-8913 is classified as a medium severity vulnerability due to its potential to allow remote authenticated users to exploit XML External Entity (XXE) attacks.
How do I fix CVE-2017-8913?
To fix CVE-2017-8913, it is recommended to update to the latest version of SAP NetWeaver AS JAVA that contains the security patches addressing this vulnerability.
What components are affected by CVE-2017-8913?
CVE-2017-8913 specifically affects the Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5.
Who is impacted by CVE-2017-8913?
Remote authenticated users of SAP NetWeaver AS JAVA 7.5 are at risk of being impacted by CVE-2017-8913.
What type of attack can CVE-2017-8913 facilitate?
CVE-2017-8913 can facilitate XML External Entity (XXE) attacks through crafted XML documents.