Overview
Openbravo ERP 2.5, 3, and possibly earlier versions contain an information disclosure vulnerability (CWE-200).
Description
CWE-200: Information Exposure Openbravo ERP version 2.5 and version 3 contain an information disclosure vulnerability. This is due to the expanded use of XML External Entity (XXE) Processing. An attacker can send specially crafted XML requests to the XML API and have the application return the contents of files on the filesystem. |
Impact
An authenticated attacker can send specially crafted XML requests to the XML API and have the application read the contents of the filesystem. This may be used to obtain unauthorized administrative access to the system. |
Solution
Apply an Update |
Disable XXE |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 3.5 | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Temporal | 2.7 | E:POC/RL:OF/RC:C |
Environmental | 0.9 | CDP:L/TD:L/CR:ND/IR:ND/AR:ND |
References
- http://cwe.mitre.org/data/definitions/200.html
- http://www.openbravo.com/
- http://wiki.openbravo.com/wiki/Updates_and_upgrades
- http://sourceforge.net/projects/openbravo/files/01-openbravo-appliances/
- https://www.owasp.org/index.php/XML_External_Entity_%28XXE%29_Processing
- https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-foss-disclosures-part-one
Acknowledgements
Thanks to Tod Beardsley and Brandon Perry of Rapid7, Inc. for reporting this vulnerability.
This document was written by Adam Rauf.
Other Information
CVE IDs: | CVE-2013-3617 |
Date Public: | 2013-10-30 |
Date First Published: | 2013-10-30 |
Date Last Updated: | 2013-11-05 21:37 UTC |
Document Revision: | 39 |