CVE-2015-2813
SAP Mobile Platform 2.3 XXE Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
XML external entity (XXE) vulnerability in SAP Mobile Platform allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125358.
Vulnerabilidad de entidad externa XML (XXE) en SAP Mobile Platform permite a atacantes remotos enviar solicitudes a servidores de intranet a través de XML manipulado, también conocido como la nota de seguridad de SAP 2125358.
SAP Mobile Platform version 2.3 suffers from an XXE injection vulnerability. An attacker can read an arbitrary file on the server by sending a correct XML request with a crafted DTD to/scc/messagebroker/http and reading the reply from the service. An attacker can perform a DoS attack (for example, an XML Entity Expansion attack). A SMB Relay attack is a type of Man-in-the-Middle attack where the attacker asks the victim to authenticate into a machine controlled by the attacker, then relays the credentials to the target. The attacker forwards the authentication information both ways, giving them access.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-04-01 CVE Reserved
- 2015-04-01 CVE Published
- 2024-06-15 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/132357/SAP-Mobile-Platform-2.3-XXE-Injection.html | X_refsource_misc |
|
http://seclists.org/fulldisclosure/2015/Jun/63 | Mailing List |
|
http://www.securityfocus.com/archive/1/535828/100/800/threaded | Mailing List | |
http://www.securityfocus.com/bid/73692 | Vdb Entry | |
https://erpscan.io/advisories/erpscan-15-005-sap-mobile-platform-xxe | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Mobile Platform Search vendor "Sap" for product "Mobile Platform" | * | - |
Affected
|