CVE-2015-2813

SAP Mobile Platform - XML External Entity Injection via Crafted XML

Title source: llm
STIX 2.1

Description

XML external entity (XXE) vulnerability in SAP Mobile Platform allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125358.

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jun/63
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/535828/100/800/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/73692

Scores

EPSS 0.0054
EPSS Percentile 67.8%

Details

Status published
Products (1)
sap/mobile_platform
Published Apr 01, 2015
Tracked Since Feb 18, 2026