CVE-2017-8913
HIGHSAP NetWeaver AS JAVA 7.5 - Authenticated XML External Entity Injection in Visual Composer VC70RUNTIME
Title source: llmDescription
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtroot/com.sap.visualcomposer.BIKit.default, aka SAP Security Note 2386873.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://erpscan.io/advisories/erpscan-17-007-sap-netweaver-java-7-5-xxe-visual-composer-vc70runtime/
Third Party Advisory x_refsource_misc
https://erpscan.io/press-center/blog/sap-cyber-threat-intelligence-report-february-2017/
Scores
CVSS v3
8.8
EPSS
0.0055
EPSS Percentile
68.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-611
Status
published
Products (1)
sap/netweaver_application_server_java
7.50
Published
May 23, 2017
Tracked Since
Feb 18, 2026