First published: Wed Apr 01 2015(Updated: )
XML external entity (XXE) vulnerability in SAP Mobile Platform allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125358.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Mobile Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2813 is considered a critical severity vulnerability due to its potential for exploitation by remote attackers.
To mitigate CVE-2015-2813, it is recommended to patch the SAP Mobile Platform to the latest version as indicated in SAP Security Note 2125358.
Exploitation of CVE-2015-2813 can lead to unauthorized access to intranet servers and potentially compromise sensitive data.
Any system using vulnerable versions of SAP Mobile Platform could be at risk for CVE-2015-2813, particularly those opening XML requests.
CVE-2015-2813 is classified as an XML External Entity (XXE) vulnerability, which allows remote access via manipulated XML input.