PT-2015-2046 · Sap · Sap Mobile Platform+1
Vahagn Vardanyan
·
Published
2015-05-13
·
Updated
2018-12-10
·
CVE-2015-6664
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SAP Afaria (affected versions not specified)
SAP Mobile Platform version 2.3
Description
The issue allows a remote attacker to inject arbitrary JavaScript code by sending a specially crafted request to the Xcomms network service. Additionally, there is an XML external entity (XXE) vulnerability in the application import functionality, which enables remote attackers to read arbitrary files and possibly have other unspecified impact via crafted XML data.
Recommendations
For SAP Afaria, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For SAP Mobile Platform version 2.3, consider restricting the application import functionality to minimize the risk of exploitation until a patch is available.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Afaria
Sap Mobile Platform