Back to search
CVE-2017-11457
Published: Jul 25, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request, aka SAP Security Note 2387249.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
97572
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now