CVE-2015-1309

SAP NetWeaver ABAP < 7.31 - XML External Entity Injection in eCATT Display XML String

Title source: llm
STIX 2.1

Description

XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers to access arbitrary files via a crafted XML request, related to ECATT_DISPLAY_XMLSTRING_REMOTE, aka SAP Note 2016638.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62469

Scores

EPSS 0.0043
EPSS Percentile 62.5%

Details

Status published
Products (1)
sap/netweaver_abap < 7.31
Published Jan 22, 2015
Tracked Since Feb 18, 2026