CVE-2013-6025

The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to read arbitrary files via a SQL statement containing an XML document with an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sybase:adaptive_server_enterprise:15.7:*:*:*:*:*:*:*

History

21 Nov 2024, 01:58

Type Values Removed Values Added
References () http://secunia.com/advisories/55377 - () http://secunia.com/advisories/55377 -
References () http://www.kb.cert.org/vuls/id/303900 - US Government Resource () http://www.kb.cert.org/vuls/id/303900 - US Government Resource
References () http://www.securityfocus.com/bid/63193 - () http://www.securityfocus.com/bid/63193 -
References () http://www.securitytracker.com/id/1029208 - () http://www.securitytracker.com/id/1029208 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/88105 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/88105 -
References () https://www.exploit-db.com/exploits/38805/ - () https://www.exploit-db.com/exploits/38805/ -

Information

Published : 2013-10-19 10:36

Updated : 2024-11-21 01:58


NVD link : CVE-2013-6025

Mitre link : CVE-2013-6025

CVE.ORG link : CVE-2013-6025


JSON object : View

Products Affected

sybase

  • adaptive_server_enterprise
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')