CVE-2013-3617

The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openbravo:openbravo_erp:2.50:*:*:*:*:*:*:*
cpe:2.3:a:openbravo:openbravo_erp:*:*:*:*:*:*:*:*
cpe:2.3:a:openbravo:openbravo_erp:2.40:*:*:*:*:*:*:*

Information

Published : 2013-11-02 12:55

Updated : 2013-11-21 10:29


NVD link : CVE-2013-3617

Mitre link : CVE-2013-3617


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

openbravo

  • openbravo_erp