XML External Entity (XXE) vulnerability in SAP NetWeaver (SAP Enterprise Portal)
CVE-2023-26461

4.9MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 March 2023

Summary

SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data. It allows the attacker to view sensitive data which is owned by certain privileges.

Affected Version(s)

NetWeaver (SAP Enterprise Portal) 7.50

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.