XML External Entity (XXE) Denial of Service Vulnerability in SAP NetWeaver 7.31 and Earlier

XML External Entity (XXE) Denial of Service Vulnerability in SAP NetWeaver 7.31 and Earlier

CVE-2013-6815 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:N/A:P

The SHSTI_UPLOAD_XML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and earlier allows remote attackers to cause a denial of service via unspecified vectors, related to an XML External Entity (XXE) issue.

Learn more about our Cis Benchmark Audit For Server Software.