3.5
CVE-2013-3617
- EPSS 21.07%
- Veröffentlicht 02.11.2013 19:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openbravo ≫ Openbravo Erp Version <= 3.0
Openbravo ≫ Openbravo Erp Version2.40
Openbravo ≫ Openbravo Erp Version2.50
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 21.07% | 0.973 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:P/I:N/A:N
|
https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats
http://www.kb.cert.org/vuls/id/533894
http://www.securityfocus.com/bid/63431