The SHSTI_UPLOAD_XML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and earlier allows remote attackers to cause a denial of service via unspecified vectors, related to an XML External Entity (XXE) issue.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 01:59
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://scn.sap.com/docs/DOC-8218 - | |
| References | () http://secunia.com/advisories/55620 - Vendor Advisory | |
| References | () https://erpscan.io/advisories/erpscan-13-020-sap-netweaver-shsti_upload_xml-xxe/ - | |
| References | () https://service.sap.com/sap/support/notes/1890819 - | 
Information
                Published : 2013-11-20 14:12
Updated : 2025-04-11 00:51
NVD link : CVE-2013-6815
Mitre link : CVE-2013-6815
CVE.ORG link : CVE-2013-6815
JSON object : View
Products Affected
                sap
- netweaver
CWE
                
                    
                        
                        CWE-20
                        
            Improper Input Validation
