PT-2015-1374 · Sap · Sap Netweaver As Java

Published

2015-05-26

·

Updated

2018-12-10

·

CVE-2015-4091

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SAP NetWeaver AS Java version 7.4
Description The issue is related to an XML external entity (XXE) vulnerability, which allows remote attackers to send TCP requests to intranet servers or have unspecified other impact via an XML request. This can be achieved by sending a specially crafted XML request to the tcsldwd~main/Main endpoint. The vulnerability is also related to "CIM UPLOAD" and can be exploited by sending specially formed TCP and XML requests, potentially allowing a remote attacker to compromise information security.
Recommendations For SAP NetWeaver AS Java version 7.4, apply the fix as described in SAP Security Note 2090851 to resolve the issue. As a temporary workaround, consider restricting access to the tcsldwd~main/Main endpoint to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-10467
CVE-2015-4091

Affected Products

Sap Netweaver As Java