PT-2020-18983 · Sap · Sap Mobile Platform
Published
2020-02-12
·
Updated
2020-02-19
·
CVE-2020-6177
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
SAP Mobile Platform version 3.0
Description
The issue arises from insufficient validation of an XML document accepted from an untrusted source, which could lead to a partial denial of service. It is noted that since SAP Mobile Platform does not allow External-Entity resolving, there is no risk of leaking the content of files on the server.
Recommendations
For SAP Mobile Platform version 3.0, consider implementing proper validation of XML documents from untrusted sources to prevent partial denial of service. As a temporary workaround, restrict the acceptance of XML documents from untrusted sources until a proper fix is applied.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Mobile Platform