ID

VAR-201310-0619


CVE

CVE-2013-6244


TITLE

SAP NetWeaver of Live Update webdynpro Vulnerability in application to read arbitrary files and directories

Trust: 0.8

sources: JVNDB: JVNDB-2013-004874

DESCRIPTION

The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWeaver 7.31 and earlier allows remote attackers to read arbitrary files and directories via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. SAP NetWeaver is prone to an information-disclosure vulnerability. An attacker can exploit this issue to gain access to sensitive information that may lead to further attacks. Given the nature of this issue, attacker may also be able to cause a denial-of-service condition

Trust: 1.89

sources: NVD: CVE-2013-6244 // JVNDB: JVNDB-2013-004874 // BID: 63302

AFFECTED PRODUCTS

vendor:sapmodel:netweaverscope:lteversion:7.31

Trust: 1.8

vendor:sapmodel:netweaverscope:eqversion:7.03

Trust: 1.6

vendor:sapmodel:netweaverscope:eqversion:6.4

Trust: 1.6

vendor:sapmodel:netweaverscope:eqversion:7.02

Trust: 1.6

vendor:sapmodel:netweaverscope:eqversion:7.0

Trust: 1.6

vendor:sapmodel:netweaverscope:eqversion:7.10

Trust: 1.6

vendor:sapmodel:netweaverscope:eqversion:7.01

Trust: 1.6

vendor:sapmodel:netweaverscope:eqversion:7.30

Trust: 1.6

vendor:sapmodel:netweaverscope:eqversion:4.0

Trust: 1.6

vendor:sapmodel:netweaverscope:eqversion:7.31

Trust: 0.6

sources: JVNDB: JVNDB-2013-004874 // CNNVD: CNNVD-201310-551 // NVD: CVE-2013-6244

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-6244
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-6244
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201310-551
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2013-6244
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2013-004874 // CNNVD: CNNVD-201310-551 // NVD: CVE-2013-6244

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2013-6244

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201310-551

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201310-551

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-004874

PATCH

title:Acknowledgments to Security Researchersurl:http://scn.sap.com/docs/DOC-8218

Trust: 0.8

sources: JVNDB: JVNDB-2013-004874

EXTERNAL IDS

db:NVDid:CVE-2013-6244

Trust: 2.7

db:SECUNIAid:55302

Trust: 1.6

db:BIDid:63302

Trust: 1.3

db:OSVDBid:98892

Trust: 1.0

db:JVNDBid:JVNDB-2013-004874

Trust: 0.8

db:CNNVDid:CNNVD-201310-551

Trust: 0.6

sources: BID: 63302 // JVNDB: JVNDB-2013-004874 // CNNVD: CNNVD-201310-551 // NVD: CVE-2013-6244

REFERENCES

url:http://en.securitylab.ru/lab/pt-2013-13

Trust: 2.4

url:https://service.sap.com/sap/support/notes/1820894

Trust: 1.6

url:http://secunia.com/advisories/55302

Trust: 1.6

url:http://scn.sap.com/docs/doc-8218

Trust: 1.6

url:http://www.securityfocus.com/bid/63302

Trust: 1.0

url:http://osvdb.org/98892

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-6244

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-6244

Trust: 0.8

url:https://www.sdn.sap.com/irj/sdn/webdynpro

Trust: 0.3

sources: BID: 63302 // JVNDB: JVNDB-2013-004874 // CNNVD: CNNVD-201310-551 // NVD: CVE-2013-6244

CREDITS

Arseny Reutov of Positive Technologies.

Trust: 0.3

sources: BID: 63302

SOURCES

db:BIDid:63302
db:JVNDBid:JVNDB-2013-004874
db:CNNVDid:CNNVD-201310-551
db:NVDid:CVE-2013-6244

LAST UPDATE DATE

2024-11-23T22:27:22.887000+00:00


SOURCES UPDATE DATE

db:BIDid:63302date:2013-12-31T00:19:00
db:JVNDBid:JVNDB-2013-004874date:2013-10-28T00:00:00
db:CNNVDid:CNNVD-201310-551date:2013-10-24T00:00:00
db:NVDid:CVE-2013-6244date:2024-11-21T01:58:55.037

SOURCES RELEASE DATE

db:BIDid:63302date:2013-10-23T00:00:00
db:JVNDBid:JVNDB-2013-004874date:2013-10-28T00:00:00
db:CNNVDid:CNNVD-201310-551date:2013-10-24T00:00:00
db:NVDid:CVE-2013-6244date:2013-10-24T00:55:02.570