First published: Wed Jun 24 2015(Updated: )
XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted XML request, aka SAP Security Note 2159601.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Mobile Platform SDK | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5068 is classified as a medium severity vulnerability due to potential unauthorized file access.
To fix CVE-2015-5068, ensure that your SAP Mobile Platform is updated to the latest version which addresses this vulnerability.
CVE-2015-5068 may allow remote attackers to read arbitrary files from the server, potentially leading to data disclosure.
Yes, there have been reports of exploit techniques that leverage this XXE vulnerability to read files on the server.
CVE-2015-5068 specifically affects SAP Mobile Platform version 3.0.