XML External Entity Vulnerability in SAP Customer Relationship Management
CVE-2013-7095
Currently unrated
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 13 December 2013
Summary
The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 is susceptible to an XML External Entity (XXE) vulnerability. This issue allows attackers to exploit the XML parsing process, potentially leading to arbitrary file access or disclosure of sensitive information as the parser processes untrusted XML input. Proper input validation and document processing controls are crucial to mitigate the risks associated with this vulnerability.
References
Timeline
Vulnerability published
Vulnerability Reserved