XML External Entity Vulnerability in SAP Mobile Platform by SAP
CVE-2015-2818

Currently unrated

Key Information:

Vendor
SAP
Vendor
CVE Published:
1 April 2015

Summary

The SAP Mobile Platform 3 is susceptible to an XML External Entity (XXE) vulnerability, allowing remote attackers to craft XML requests that can access intranet servers. This issue can potentially lead to unauthorized data exposure. SAP Security Note 2125513 provides further details and mitigation strategies that can be employed to safeguard against this vector of attack.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.