6.8
CVSSv2

CVE-2015-6664

Published: 24/08/2015 Updated: 10/12/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

XML external entity (XXE) vulnerability in the application import functionality in SAP Mobile Platform 2.3 allows remote malicious users to read arbitrary files and possibly have other unspecified impact via crafted XML data, aka SAP Security Note 2152227.

Vulnerable Product Search on Vulmon Subscribe to Product

sap mobile platform 2.3

Exploits

SAP Mobile Platform version 23 suffers from an XML external entity injection vulnerability ...