5
CVSSv2

CVE-2013-6244

Published: 24/10/2013 Updated: 31/10/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWeaver 7.31 and previous versions allows remote malicious users to read arbitrary files and directories via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Vulnerable Product Search on Vulmon Subscribe to Product

sap netweaver 7.03

sap netweaver 7.02

sap netweaver

sap netweaver 6.4

sap netweaver 4.0

sap netweaver 7.01

sap netweaver 7.0

sap netweaver 7.30

sap netweaver 7.10

Github Repositories

Lorem ipsum dolor sit amet

Idea to find the vendor and application from CVEs REQUIREMENTS: pip install xmltodict Example: $ python refpy | tail -10 CVE-2013-6129 [[u'vbulletin', u'vbulletin', u'41'], [u'vbulletin', u'vbulletin', u'50']] CVE-2013-6170 [[u'juni