CVE-2015-2811
published 2015-04-01CVE-2015-2811: XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
2.38%
82.0th percentile
XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2111939.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | — | — |
| sap | netweaver_enterprise_portal | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_apache5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vjxx-m4c9-mp2v: XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7
ghsa_unreviewed·2022-05-14
CVE-2015-2811 [MEDIUM] GHSA-vjxx-m4c9-mp2v: XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7
XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2111939.
Apache
Apache tika: CVE-2015-3271
vendor_apache·CVSS 5.3
CVE-2015-3271 [MEDIUM] Apache tika: CVE-2015-3271
Apache tika: CVE-2015-3271
Remote Access to host files via tika-server Tim Allison 1.9?-1.10 PDFBOX-2811 Apache PDFBox - Infinite Loop Andreas Lehmkühler ?-1.10 PDFBOX-2200 Apache PDFBox - Slowly building memory leak because of static caching of fonts Matthew Buckett ?-1.6 TIKA-1471 Apache PDFBox - OOM with corrupt PDF Alan Burlison ?-1.6 TIKA-788 Infinite Loop in DWG Stas Shaposhnikov ?-1.4? TIKA-1132 Apache POI - Nearly Infinite Loop in XLS Ryan Krueger ?-1.4 TIKA-1179 Infinite Loop in corrupt MP3 Marius Dumitru Florea ?-1.4 TIKA-866 OOM reading Tika config file Stephan Mühlstrasser ?-1.1 Third party vulnerabilities that may or may not be triggerable via regular use of Apache Tika. CVE or Vulnerability Description Reporter Affected Versions
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/132358/SAP-NetWeaver-Portal-7.31-XXE-Injection.htmlhttp://seclists.org/fulldisclosure/2015/Jun/64http://www.securityfocus.com/archive/1/535827/100/800/threadedhttp://www.securityfocus.com/bid/73691https://erpscan.io/advisories/erpscan-15-006-sap-netweaver-portal-reportxmlviewer-xxe/http://packetstormsecurity.com/files/132358/SAP-NetWeaver-Portal-7.31-XXE-Injection.htmlhttp://seclists.org/fulldisclosure/2015/Jun/64http://www.securityfocus.com/archive/1/535827/100/800/threadedhttp://www.securityfocus.com/bid/73691https://erpscan.io/advisories/erpscan-15-006-sap-netweaver-portal-reportxmlviewer-xxe/
2015-04-01
Published