CVE-2015-5068
SAP Mobile Platform 3 XXE Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted XML request, aka SAP Security Note 2159601.
Vulnerabilidad de entidad externa XML (XXE) en SAP Mobile Platform 3 permite a atacantes remotos leer ficheros arbitrarios o posiblemente tener otro impacto no especificado a través de una solicitud XML manipulada, también conocido como la nota de seguridad de SAP 2159601.
SAP NetWeaver AS Java version 7.4 suffers from multiple XXE vulnerabilities. An attacker can read an arbitrary file on a server by sending a correct XML request with a crafted DTD and reading the response from the service. An attacker can perform a DoS attack (for example, XML Entity Expansion). An SMB Relay attack is a type of Man-in-the-Middle attack where the attacker asks the victim to authenticate into a machine controlled by the attacker, then relays the credentials to the target. The attacker forwards the authentication information both ways and gets access.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-06-24 CVE Reserved
- 2015-06-24 CVE Published
- 2015-09-10 First Exploit
- 2024-08-06 CVE Updated
- 2024-09-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/133514/SAP-Mobile-Platform-3-XXE-Injection.html | X_refsource_misc |
|
http://seclists.org/fulldisclosure/2015/Sep/36 | Mailing List |
|
http://www.securityfocus.com/bid/75166 | Vdb Entry | |
https://erpscan.io/advisories/erpscan-15-014-sap-mobile-platform-3-xxe-in-add-repository | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/133514 | 2015-09-10 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://scn.sap.com/community/security/blog/2015/06/11/sap-security-notes-june-2015 | 2018-12-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Mobile Platform Search vendor "Sap" for product "Mobile Platform" | 3.0 Search vendor "Sap" for product "Mobile Platform" and version "3.0" | - |
Affected
|