SAP Security Note
High priority
SAP security note 2125513, "XXE vulnerability in SAP Mobile Platform", is released on 13.03.2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Some of the URLs used for Mobiliser administration within SAP Mobile Platform (SMP) can receive XML documents in the request, which are processed by an XML parser. The configuration settings for the XML parser were incorrect, allowing maliciously constructed XML documents to cause undesirable information disclosure and denial of service (DoS) issues.
Solution
For SAP Mobile Platform 3.0, upgrade your SMP server installation to SMP 3.0 SP06.
For standalone Mobiliser installations (SYBASE MOBILISER PLATFORM), download and install one of the following patches from the SAP Service Marketplace:
- EBF 24054 – MobiliserPlatform 5.0 SP02 PL08 (Mobiliser 5.0)
- EBF 24055 – MobiliserPlatform 5.1 SP02 PL08 (Mobiliser 5.1)
- EBF 24056 – MobiliserPlatform 5.1 SP03 PL08 (Mobiliser 5.1.3)
Reason and prerequisites
The issue is caused by a program error in the ‘ValidationComponent’ due to the incorrect use of an XML parser. By default, the parser opens external entities referenced within an XML input, which can lead to malicious content being parsed. This malicious content can reference internal resources, such as files, resulting in information disclosure or enabling a denial of service attack by rendering application content temporarily unavailable.
CVSS
Score 5.5 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:P
Affected components
- SYBASE_MOBILISER_PLATFORM: Versions 5.0 to 5.1
- SAP_MOBILE_PLATFORM_RUNTIME: Version 3.0 and above
Full note on SAP: SAP Support Launchpad note 2125513
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




