CVE-2015-2818: Medium severity sap mobile platform sdk vulnerability
XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125513.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2818?
CVE-2015-2818 has a medium severity rating due to its potential for exploitation via crafted XML to access intranet servers.
How do I fix CVE-2015-2818?
To fix CVE-2015-2818, upgrade to a version of SAP Mobile Platform 3.0 that contains the relevant security patches provided in SAP Security Note 2125513.
What types of attacks can CVE-2015-2818 facilitate?
CVE-2015-2818 can facilitate XML external entity (XXE) attacks that allow attackers to send requests to internal network resources.
Who is affected by CVE-2015-2818?
CVE-2015-2818 affects users of SAP Mobile Platform version 3.0 that have not applied the necessary security updates.
What is an XML external entity (XXE) vulnerability as seen in CVE-2015-2818?
An XML external entity (XXE) vulnerability allows an attacker to exploit XML parsers to access sensitive data or execute attacks on the server.