SAP Mobile Platform 2.3 XXE Injection

Discussion in 'News Aggregator' started by Packet Storm, 19 Jun 2015.

  1. Packet Storm

    Packet Storm Guest

    SAP Mobile Platform 2.3 suffers from an XXE injection vulnerability. n attacker can read an arbitrary file on the server by sending a correct XML request with a crafted DTD to/scc/messagebroker/http and reading the reply from the service. An attacker can perform a DoS attack (for example, an XML Entity Expansion attack). A SMB Relay attack is a type of Man-in-the-Middle attack where the attacker asks the victim to authenticate into a machine controlled by the attacker, then relays the credentials to the target. The attacker forwards the authentication information both ways, giving them access.

    Continue reading...
     

Share This Page

Loading...