PT-2017-8946 · Sap · Sap Business One For Android
Ravindra Singh Rathore
·
Publicado
2017-05-25
·
Atualizado
2019-07-08
·
CVE-2016-6256
CVSS v3.1
9.6
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Business One for Android version 1.2.3
Description
The issue allows remote attackers to conduct XML External Entity (XXE) attacks. This is achieved by sending crafted XML data in a request to the "B1iXcellerator/exec/soap/vP.001sap0003.in WCSX/com.sap.b1i.vplatform.runtime/INB WS CALL SYNC XPT/INB WS CALL SYNC XPT.ipo/proc" API endpoint.
Recommendations
For SAP Business One for Android version 1.2.3, consider restricting access to the vulnerable API endpoint "B1iXcellerator/exec/soap/vP.001sap0003.in WCSX/com.sap.b1i.vplatform.runtime/INB WS CALL SYNC XPT/INB WS CALL SYNC XPT.ipo/proc" until a patch is available.
Exploit
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap Business One For Android