CVE-2015-4091
XML external entity (XXE) vulnerability in SAP NetWeaver AS Java 7.4 allows remote attackers to send TCP requests to intranet servers or possibly have unspecified other impact via an XML request to tc~sld~wd~main/Main, related to "CIM UPLOAD," aka SAP…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
XML external entity (XXE) vulnerability in SAP NetWeaver AS Java 7.4 allows remote attackers to send TCP requests to intranet servers or possibly have unspecified other impact via an XML request to tc~sld~wd~main/Main, related to "CIM UPLOAD," aka SAP Security Note 2090851.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.91% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- sap/sap netweaver application server java
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/133122/SAP-NetWeaver-AS-Java-XXE-Injection.html
- http://seclists.org/fulldisclosure/2015/May/96
- http://www.securityfocus.com/archive/1/536239/100/0/threaded
- http://www.securityfocus.com/bid/74850
- https://erpscan.io/advisories/erpscan-15-013-sap-netweaver-as-java-cim-upload-xxe
- http://packetstormsecurity.com/files/133122/SAP-NetWeaver-AS-Java-XXE-Injection.html
- http://seclists.org/fulldisclosure/2015/May/96
- http://www.securityfocus.com/archive/1/536239/100/0/threaded
- http://www.securityfocus.com/bid/74850
- https://erpscan.io/advisories/erpscan-15-013-sap-netweaver-as-java-cim-upload-xxe
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.