Security Advisory

CVE-2013-6025

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2013-10-19 10:00:00
Last updated 2024-08-06 17:29:42
Assigner certcc
CVSS score not scored
State PUBLISHED

Description

The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to read arbitrary files via a SQL statement containing an XML document with an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.