3.5
CVE-2013-3617
- EPSS 56.74%
- Veröffentlicht 02.11.2013 19:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openbravo ≫ Openbravo Erp Version <= 3.0
Openbravo ≫ Openbravo Erp Version2.40
Openbravo ≫ Openbravo Erp Version2.50
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 56.74% | 0.981 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:P/I:N/A:N
|