CVE-2015-7968
SAP Application Server vulnerability analysis and mitigation

Overview

The vulnerability (CVE-2015-7968) affects SAP NetWeaver Application Server's nwbc_ext2int module, which is used for displaying data in side panels and converting external UI elements to internal representations. The vulnerability was discovered in June 2015 and allows XML External Entity (XXE) attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI (Integrity Labs).

Technical details

The XXE vulnerability requires authentication and can be exploited by sending crafted XML content to the nwbc_ext2int endpoint. The vulnerability exists due to improper handling of XML External Entity entries when parsing XML input. The CVSS v3.1 base score is 4.3 (MEDIUM) with vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N. The vulnerability is classified under CWE-611 (Improper Restriction of XML External Entity Reference) (NVD).

Impact

When successfully exploited, the vulnerability allows authenticated attackers to read arbitrary files on the server through XML parsing. Since SAP is Java-based, the XML parser allows reading both files and directories. The access is restricted to the user context running SAP, but attackers could potentially access configuration files and SSH private keys, which could lead to further system compromise (Integrity Labs).

Mitigation and workarounds

SAP has addressed this vulnerability by releasing Security Note 2183189. Users should apply the patch provided in this security note to protect their systems (Integrity Labs).

Additional resources


SourceThis report was generated using AI

Related SAP Application Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-6262HIGH8.8
  • SAP Application ServerSAP Application Server
  • cpe:2.3:a:sap:application_server
NoNoMay 12, 2020
CVE-2007-3615HIGH7.8
  • SAP Application ServerSAP Application Server
  • cpe:2.3:a:sap:sap_web_application_server
NoNoJul 06, 2007
CVE-2009-4603MEDIUM5
  • SAP Application ServerSAP Application Server
  • cpe:2.3:a:sap:sap_kernel
NoYesJan 12, 2010
CVE-2015-7968MEDIUM4.3
  • SAP Application ServerSAP Application Server
  • cpe:2.3:a:sap:netweaver_application_server
NoYesMar 09, 2020
CVE-2008-2421MEDIUM4.3
  • SAP Application ServerSAP Application Server
  • cpe:2.3:a:sap:sap_web_application_server
NoNoMay 23, 2008

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management