cve/2016/CVE-2016-4014.md
2024-06-18 02:51:15 +02:00

920 B

CVE-2016-4014

Description

XML external entity (XXE) vulnerability in the UDDI component in SAP NetWeaver JAVA AS 7.4 allows remote attackers to cause a denial of service (system hang) via a crafted DTD in an XML request to uddi/api/replication, aka SAP Security Note 2254389.

POC

Reference

Github