[ERPSCAN-15-020] SAP Mobile Platform 2.3 – XXE in application import

Posted by ERPScan inc on Nov 24

Application: SAP Mobile Platform 2.3
Versions Affected: SAP Mobile Platform 2.3, probably others
Vendor URL: http://SAP.com
Bugs: XML External Entity
Send: 25.02.2015
Reported: 25.02.2015
Vendor response: 25.02.2015
Date of Public Advisory: 11.08.2015
Reference: SAP Security Note 2152227
Author: Vahagn Vardanyan (ERPScan)

Description

1. ADVISORY INFORMATION
Title: SAP Mobile Platform 2.3
Advisory…