PT-2017-8946 · Sap · Sap Business One For Android

Ravindra Singh Rathore

·

Published

2017-05-25

·

Updated

2019-07-08

·

CVE-2016-6256

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Business One for Android version 1.2.3
Description The issue allows remote attackers to conduct XML External Entity (XXE) attacks. This is achieved by sending crafted XML data in a request to the "B1iXcellerator/exec/soap/vP.001sap0003.in WCSX/com.sap.b1i.vplatform.runtime/INB WS CALL SYNC XPT/INB WS CALL SYNC XPT.ipo/proc" API endpoint.
Recommendations For SAP Business One for Android version 1.2.3, consider restricting access to the vulnerable API endpoint "B1iXcellerator/exec/soap/vP.001sap0003.in WCSX/com.sap.b1i.vplatform.runtime/INB WS CALL SYNC XPT/INB WS CALL SYNC XPT.ipo/proc" until a patch is available.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-6256

Affected Products

Sap Business One For Android