CVE-2015-5068: High severity sap mobile platform sdk vulnerability
Published Jun 24, 2015
·Updated
XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted XML request, aka SAP Security Note 2159601.
Affected Software
1 affected component
SAP Mobile Platform=3.0
Event History
Jun 24, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5068?
CVE-2015-5068 is classified as a medium severity vulnerability due to potential unauthorized file access.
2
How do I fix CVE-2015-5068?
To fix CVE-2015-5068, ensure that your SAP Mobile Platform is updated to the latest version which addresses this vulnerability.
3
What impact does CVE-2015-5068 have on my system?
CVE-2015-5068 may allow remote attackers to read arbitrary files from the server, potentially leading to data disclosure.
4
Are there any known exploits for CVE-2015-5068?
Yes, there have been reports of exploit techniques that leverage this XXE vulnerability to read files on the server.
5
What applications are affected by CVE-2015-5068?
CVE-2015-5068 specifically affects SAP Mobile Platform version 3.0.