SAP Mobile Platform 3 XXE Injection

Discussion in 'News Aggregator' started by Packet Storm, 10 Sep 2015.

  1. Packet Storm

    Packet Storm Guest

    SAP NetWeaver AS Java version 7.4 suffers from multiple XXE vulnerabilities. An attacker can read an arbitrary file on a server by sending a correct XML request with a crafted DTD and reading the response from the service. An attacker can perform a DoS attack (for example, XML Entity Expansion). An SMB Relay attack is a type of Man-in-the-Middle attack where the attacker asks the victim to authenticate into a machine controlled by the attacker, then relays the credentials to the target. The attacker forwards the authentication information both ways and gets access.

    Continue reading...
     

Share This Page

Loading...