First published: Wed Apr 01 2015(Updated: )
XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125513.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Mobile Platform SDK | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2818 has a medium severity rating due to its potential for exploitation via crafted XML to access intranet servers.
To fix CVE-2015-2818, upgrade to a version of SAP Mobile Platform 3.0 that contains the relevant security patches provided in SAP Security Note 2125513.
CVE-2015-2818 can facilitate XML external entity (XXE) attacks that allow attackers to send requests to internal network resources.
CVE-2015-2818 affects users of SAP Mobile Platform version 3.0 that have not applied the necessary security updates.
An XML external entity (XXE) vulnerability allows an attacker to exploit XML parsers to access sensitive data or execute attacks on the server.