PT-2015-1374 · Sap · Sap Netweaver As Java
Published
2015-05-26
·
Updated
2018-12-10
·
CVE-2015-4091
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver AS Java version 7.4
Description
The issue is related to an XML external entity (XXE) vulnerability, which allows remote attackers to send TCP requests to intranet servers or have unspecified other impact via an XML request. This can be achieved by sending a specially crafted XML request to the tcsldwd~main/Main endpoint. The vulnerability is also related to "CIM UPLOAD" and can be exploited by sending specially formed TCP and XML requests, potentially allowing a remote attacker to compromise information security.
Recommendations
For SAP NetWeaver AS Java version 7.4, apply the fix as described in SAP Security Note 2090851 to resolve the issue.
As a temporary workaround, consider restricting access to the tcsldwd~main/Main endpoint to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver As Java