The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/89703 | vdb entry |
http://www.securitytracker.com/id/1029488 | vdb entry |
http://scn.sap.com/docs/DOC-8218 | |
http://secunia.com/advisories/56064 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/64265 | vdb entry |
https://service.sap.com/sap/support/notes/1909665 | |
https://erpscan.io/advisories/erpscan-13-025-sap-crm-crm_flex_data-xxe/ |