vendor:
SAP NetWeaver AS JAVA
by:
Vahagn Vardanyan (ERPScan)
6,4
CVSS
HIGH
XXE
611
CWE
Product Name: SAP NetWeaver AS JAVA
Affected Version From: SAP NetWeaver AS JAVA 7.5
Affected Version To: SAP NetWeaver AS JAVA 7.5
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
[ERPSCAN-16-034] SAP NetWeaver AS JAVA – XXE vulnerability in BC-BMT-BPM-DSK component
It is possible, that an attacker can perform a DoS attack (for example, an XML Entity expansion attack) and an SMB Relay attack is a type of man-in-the-middle attack where an attacker asks a victim to authenticate to a machine controlled by the attacker, then relays the credentials to the target. The attacker forwards the authentication information both ways, giving him access.
Mitigation:
Install SAP Security Note 2296909