CVE-2015-8840
Last modified
CVE-2015-8840 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sensitive information, gain privileges, or possibly have unspecified other impact via requests to (1) webcontent/cas/cas_enter.jsp, (2) webcontent/cas/cas_validate.jsp, or (3) webcontent/aas/aas_store.jsp, aka SAP Security Note 1945215.. EPSS estimates a 1.31% chance of exploitation in the next 30 days.
Description
The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sensitive information, gain privileges, or possibly have unspecified other impact via requests to (1) webcontent/cas/cas_enter.jsp, (2) webcontent/cas/cas_validate.jsp, or (3) webcontent/aas/aas_store.jsp, aka SAP Security Note 1945215.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server Java | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-8840?
How severe is CVE-2015-8840?
How do I fix CVE-2015-8840?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-8834Cross-site scripting (XSS) vulnerability in wp-includes/wp-d…
- CVE-2015-8835The make_http_soap_request function in ext/soap/php_http.c i…
- CVE-2015-8836Integer overflow in the isofs_real_read_zf function in isofs…
- CVE-2015-8837Stack-based buffer overflow in the isofs_real_readdir functi…
- CVE-2015-8838ext/mysqlnd/mysqlnd.c in PHP before 5.4.43, 5.5.x before 5.5…
- CVE-2015-8839Multiple race conditions in the ext4 filesystem implementati…5.1
- CVE-2015-8841Heap-based buffer overflow in the Archive support module in …9.8
- CVE-2015-8842tmpfiles.d/systemd.conf in systemd before 229 uses weak perm…
- CVE-2015-8843The Foxit Cloud Update Service (FoxitCloudUpdateService) in …
- CVE-2015-8844The signal implementation in the Linux kernel before 4.3.5 o…
- CVE-2015-8845The tm_reclaim_thread function in arch/powerpc/kernel/proces…
- CVE-2015-8851node-uuid before 1.4.4 uses insufficiently random data to cr…7.5
Are you affected by CVE-2015-8840?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
