Overview
SAP Sybase Adaptive Server Enterprise Version 15.7 ESD 2 and possibly earlier versions contains an XML injection vulnerability (CWE-91).
Description
CWE-611: Improper Restriction of XML External Entity Reference ('XXE') SAP Sybase Adaptive Server Enterprise (ASE) Version 15.7 ESD 2 contains an XML injection vulnerability, which can lead to information exposure. This is due to the expanded use of XML External Entity (XXE) Processing. The XMLParse procedure is vulnerable to attack. Using a specially crafted SQL request, an authenticated attacker may be able to read files with the permissions of the user running the ASE application. |
Impact
An authenticated attacker may be able to use the vulnerabilities to read user credentials. This may be used to obtain unauthorized administrative or privileged access to the system. |
Solution
Apply an Update |
Disable XXE |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 2.3 | AV:A/AC:M/Au:S/C:P/I:N/A:N |
Temporal | 1.8 | E:POC/RL:OF/RC:C |
Environmental | 1.4 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Igor Bulatenko for reporting this vulnerability.
This document was written by Adam Rauf.
Other Information
CVE IDs: | CVE-2013-6025 |
Date Public: | 2013-10-01 |
Date First Published: | 2013-10-17 |
Date Last Updated: | 2013-12-05 22:06 UTC |
Document Revision: | 30 |