CVE-2016-6256: XEE
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.inWCSX/com.sap.b1i.vplatform.runtime/INBWSCALLSYNCXPT/INBWSCALLSYNCXPT.ipo/proc, aka SAP Security Note 2378065.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6256?
CVE-2016-6256 is classified as a medium severity vulnerability that allows for XML External Entity (XXE) attacks.
How do I fix CVE-2016-6256?
To fix CVE-2016-6256, update to the latest version of SAP Business One for Android that addresses this vulnerability.
What types of attacks can be executed due to CVE-2016-6256?
CVE-2016-6256 allows remote attackers to conduct XML External Entity (XXE) attacks, potentially leading to data exposure.
Which version of SAP Business One is affected by CVE-2016-6256?
CVE-2016-6256 specifically affects SAP Business One version 1.2.3 on Android.
What is the impact of CVE-2016-6256 on users?
The impact of CVE-2016-6256 on users includes potential unauthorized access to sensitive data through crafted XML requests.