6.8
CVSSv2

CVE-2015-6662

Published: 24/08/2015 Updated: 10/12/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

XML external entity (XXE) vulnerability in SAP NetWeaver Portal 7.4 allows remote malicious users to read arbitrary files and possibly have other unspecified impact via crafted XML data, aka SAP Security Note 2168485.

Vulnerable Product Search on Vulmon Subscribe to Product

sap netweaver 7.40

Exploits

SAP NetWeaver version 74 suffers from an XML external entity injection vulnerability ...