PT-2013-5930 · Sap · Sap Sybase Adaptive Server Enterprise

Igor Bulatenko

·

Publicado

2013-10-19

·

Atualizado

2017-09-13

·

CVE-2013-6025

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Sybase Adaptive Server Enterprise (ASE) version 15.7 ESD 2
Description The issue allows remote authenticated users to read arbitrary files via a SQL statement containing an XML document with an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Recommendations For SAP Sybase Adaptive Server Enterprise (ASE) version 15.7 ESD 2, consider restricting access to the XMLParse procedure to minimize the risk of exploitation. As a temporary workaround, consider disabling the XMLParse procedure until a patch is available.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-6025

Produtos afetados

Sap Sybase Adaptive Server Enterprise