PT-2017-8946 · Sap · Sap Business One For Android

Ravindra Singh Rathore

·

Publicado

2017-05-25

·

Atualizado

2019-07-08

·

CVE-2016-6256

CVSS v3.1

9.6

Crítica

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Business One for Android version 1.2.3
Description The issue allows remote attackers to conduct XML External Entity (XXE) attacks. This is achieved by sending crafted XML data in a request to the "B1iXcellerator/exec/soap/vP.001sap0003.in WCSX/com.sap.b1i.vplatform.runtime/INB WS CALL SYNC XPT/INB WS CALL SYNC XPT.ipo/proc" API endpoint.
Recommendations For SAP Business One for Android version 1.2.3, consider restricting access to the vulnerable API endpoint "B1iXcellerator/exec/soap/vP.001sap0003.in WCSX/com.sap.b1i.vplatform.runtime/INB WS CALL SYNC XPT/INB WS CALL SYNC XPT.ipo/proc" until a patch is available.

Exploit

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-6256

Produtos afetados

Sap Business One For Android