CVE-2014-8590 Information
Feb 14, 2021
cve
Description
XML external entity (XXE) vulnerability in the Web Service Navigator in SAP NetWeaver Application Server (AS) Java allows remote attackers to access arbitrary files via a crafted request.
Reference
http://blog.onapsis.com/analyzing-sap-security-notes-october-2014-edition/ http://www.securityfocus.com/bid/71023 https://erpscan.io/advisories/erpscan-14-015-sap-netweaver-as-java-xxe/ https://erpscan.io/press-center/blog/sap-critical-patch-update-october-2014/ https://exchange.xforce.ibmcloud.com/vulnerabilities/98581 https://service.sap.com/sap/support/notes/2045176
Share on: