The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to read arbitrary files via a SQL statement containing an XML document with an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
References
Configurations
History
21 Nov 2024, 01:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/55377 - | |
References | () http://www.kb.cert.org/vuls/id/303900 - US Government Resource | |
References | () http://www.securityfocus.com/bid/63193 - | |
References | () http://www.securitytracker.com/id/1029208 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/88105 - | |
References | () https://www.exploit-db.com/exploits/38805/ - |
Information
Published : 2013-10-19 10:36
Updated : 2024-11-21 01:58
NVD link : CVE-2013-6025
Mitre link : CVE-2013-6025
CVE.ORG link : CVE-2013-6025
JSON object : View
Products Affected
sybase
- adaptive_server_enterprise
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')