XML External Entity Vulnerability in SAP Customer Relationship Management
CVE-2013-7095

Currently unrated

Key Information:

Vendor
SAP
Vendor
CVE Published:
13 December 2013

Summary

The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 is susceptible to an XML External Entity (XXE) vulnerability. This issue allows attackers to exploit the XML parsing process, potentially leading to arbitrary file access or disclosure of sensitive information as the parser processes untrusted XML input. Proper input validation and document processing controls are crucial to mitigate the risks associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.