CVE-2015-1309 Information
Feb 14, 2021
cve
Description
XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers to access arbitrary files via a crafted XML request related to ECATT_DISPLAY_XMLSTRING_REMOTE aka SAP Note 2016638.
Reference
http://secunia.com/advisories/62469 https://erpscan.io/advisories/erpscan-15-001-sap-netweaver-ecatt_display_xmlstring_remote-xxe/ https://erpscan.io/press-center/blog/sap-critical-patch-update-january-2015/
Share on: