XML External Entity Vulnerability in SAP CRM Gwsync
CVE-2014-1962
Currently unrated
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 14 February 2014
What is CVE-2014-1962?
The Gwsync component of SAP CRM version 7.02 EHP 2 is susceptible to an XML External Entity (XXE) vulnerability, which enables remote attackers to exploit unspecified vectors to gain unauthorized access to sensitive information. This security issue results from the improper handling of XML input, potentially allowing attackers to manipulate server responses or access confidential data stored on the server.
References
Timeline
Vulnerability published
Vulnerability Reserved